inspectorGHSA-7f8r-222p-6f5g
MCP Inspector proxy server lacks authentication between the Inspector client and proxy
CriticalCVE-2025-49596 · Published Jun 13, 2025 · updated Jul 9, 2025
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| @modelcontextprotocol/inspector npm | < 0.14.1 | 0.14.1 |
Details and references
Versions of MCP Inspector below 0.14.1 are vulnerable to remote code execution due to lack of authentication between the Inspector client and proxy, allowing unauthenticated requests to launch MCP commands over stdio. Users should immediately upgrade to version 0.14.1 or later to address these vulnerabilities. Credit: Rémy Marot <bughunters@tenable.com>
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-306
- Also known as
- CVE-2025-49596
- github.com/modelcontextprotocol/inspector/security/advisories/GHSA-7f8r-222p-6f5g
- nvd.nist.gov/vuln/detail/CVE-2025-49596
- github.com/modelcontextprotocol/inspector/commit/50df0e1ec488f3983740b4d28d2a968f12eb8979
- github.com/modelcontextprotocol/inspector
- thenewstack.io/mcp-vulnerability-exposes-the-ai-untrusted-code-crisis
- www.oligo.security/blog/critical-rce-vulnerability-in-anthropic-mcp-inspector-cve-2025-49596
More inspector advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 82025 | MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server CVE-2025-58444Highfixed in 0.16.6 | High | 0.16.6 |