Skip to content

Bump fastmcp from 2.13.1 to 2.14.3 (with mcp 1.25.0)#57

Merged
wasaga merged 1 commit intomainfrom
fix/fastmcp-cve-2025-66416
Jan 20, 2026
Merged

Bump fastmcp from 2.13.1 to 2.14.3 (with mcp 1.25.0)#57
wasaga merged 1 commit intomainfrom
fix/fastmcp-cve-2025-66416

Conversation

@wasaga
Copy link
Copy Markdown
Contributor

@wasaga wasaga commented Jan 20, 2026

Summary

  • Updates fastmcp from 2.13.1 to 2.14.3
  • Updates mcp from 1.23.0 to 1.25.0 (required dependency for fastmcp 2.14+)
  • Updates py-key-value-aio from 0.2.8 to 0.3.0 (required dependency for fastmcp 2.14+)
  • Updates py-key-value-shared from 0.2.8 to 0.3.0 (required dependency for fastmcp 2.14+)

Security

Fixes Dependabot alert #14: FastMCP updated to MCP 1.23+ due to CVE-2025-66416

Notes

fastmcp 2.14+ requires mcp>=1.24.0 and py-key-value-aio>=0.3.0, so all dependent packages are updated together.

Test plan

  • CI passes

Fixes Dependabot alert #14: FastMCP updated to MCP 1.23+ due to CVE-2025-66416

Also updates:
- py-key-value-aio: 0.2.8 → 0.3.0 (required by fastmcp 2.14+)
- py-key-value-shared: 0.2.8 → 0.3.0 (required by fastmcp 2.14+)
@wasaga wasaga merged commit 2af9ac2 into main Jan 20, 2026
5 checks passed
@wasaga wasaga deleted the fix/fastmcp-cve-2025-66416 branch January 20, 2026 20:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants