Skip to content
inspectorGHSA-g9hg-qhmf-q45m

MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server

HighCVE-2025-58444 · Published Sep 8, 2025 · updated Sep 26, 2025

GitHub advisory

Affected versions

PackageAffectedFixed in
@modelcontextprotocol/inspector
npm
< 0.16.60.16.6
Details and references

An XSS flaw exists in the MCP Inspector local development tool when it renders a redirect URL returned by a remote MCP server. If the Inspector connects to an untrusted server, a crafted redirect can inject script into the Inspector context and, via the built-in proxy, be leveraged to trigger arbitrary command execution on the developer machine. Version 0.16.6 hardens URL handling/validation and prevents script execution. > Thank you to the following researchers for their reports and contributions: > * Raymond (Veria Labs) > * Gavin Zhong, <superboyzjc@gmail.com> & Shuyang Wang, <swang@obsidiansecurity.com>.

CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-79, CWE-84, CWE-94
Also known as
CVE-2025-58444

More inspector advisories

All
DateAdvisory
Jun 132025MCP Inspector proxy server lacks authentication between the Inspector client and proxy
CVE-2025-49596Criticalfixed in 0.14.1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.