Remote Code Execution Vulnerability in MCP Inspector by Model Context Protocol
CVE-2025-49596
9.4CRITICAL
What is CVE-2025-49596?
The MCP Inspector, a tool designed for testing and debugging MCP servers, is susceptible to remote code execution in versions prior to 0.14.1. The vulnerability arises from an absence of authentication between the Inspector client and the proxy, which allows unauthorized users to send commands to the MCP servers. This flaw enables malicious actors to exploit the system through unauthenticated requests. It is imperative for users to upgrade to version 0.14.1 or later to secure their environments against potential threats.
Affected Version(s)
inspector < 0.14.1