CVE-2025-64340 — FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, server names containing shell metacharacters (e.g., &) can cause command injection on Windows when passed t — CVE Database · The Intelligence Room