Skip to content

fix(deps): bump fastmcp 2.7.0 -> 3.4.7 to clear CRITICAL SSRF/path-traversal CVE - #190

Open
sairam0424 wants to merge 1 commit into
qdrant:masterfrom
sairam0424:fix/bump-fastmcp-3.4.7-cve-173
Open

sairam0424 wants to merge 1 commit into
qdrant:masterfrom
sairam0424:fix/bump-fastmcp-3.4.7-cve-173

Conversation

@sairam0424

Copy link
Copy Markdown

Summary

mcp-server-qdrant@0.8.1 exactly pins fastmcp==2.7.0, which is affected by GHSA-vv7q-7jx5-f767 (CRITICAL, SSRF and path traversal in the OpenAPI provider). Fixed upstream in 3.2.0.

This bumps the pin to 3.4.7 — the latest 3.x release — rather than the current 4.0.0.

Why 3.4.7 and not 4.0.0

The open Dependabot PR (#186, fastmcp 2.7.0 -> 4.0.0) is currently failing CI. Root cause: fastmcp==4.0.0 depends on fastmcp-slim, which requires pydantic>=2.12.0. That conflicts with this project's own pydantic>=2.10.6,<2.12.0 pin (added in #97), so uv sync fails dependency resolution outright on every Python version in the test matrix.

fastmcp==3.4.7 has no pydantic constraint at all, clears the CVE, and needs no code changes — it sidesteps the conflict blocking #186 without pulling in FastMCP 4's breaking changes.

Validation

  • uv lock regenerated cleanly for the new pin, no conflicts
  • Full test suite passes locally: 24 passed
  • ruff check ., ruff format --check ., isort --check-only .: all clean
  • mypy src: reports the same 9 pre-existing errors present on a clean master checkout (in qdrant.py, filters.py, mcp_server.py, fastembed.py) — confirmed unrelated to this change, not introduced by it

Closes #173

🤖 Generated with Claude Code

…aversal CVE

fastmcp==2.7.0 is affected by GHSA-vv7q-7jx5-f767 (CRITICAL, SSRF and
path traversal in the OpenAPI provider), fixed upstream in 3.2.0.

3.4.7 (the latest 3.x release) is used instead of the current 4.0.0
because 4.0.0 pulls in fastmcp-slim, which requires pydantic>=2.12.0.
That conflicts with this project's own pydantic>=2.10.6,<2.12.0 pin
and is why the open Dependabot PR (qdrant#186, fastmcp 2.7.0 -> 4.0.0) fails
CI with an unsatisfiable dependency resolution. 3.4.7 has no pydantic
constraint, clears the CVE, and requires no code changes.

- uv.lock regenerated for the new pin
- Full test suite passes locally: 24 passed
- ruff check / ruff format --check / isort --check-only: all clean
- mypy reports the same 9 pre-existing errors as on master, unrelated
  to this change (confirmed against a clean checkout)

Closes qdrant#173

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bump fastmcp==2.7.0 to clear CRITICAL SSRF/path traversal and 14 OSV findings

2 participants