Cross-Site Scripting Vulnerability in MCP Inspector Tool by Model Context Protocol
CVE-2025-58444
8.6HIGH
What is CVE-2025-58444?
The MCP Inspector, a developer tool designed for testing and debugging MCP servers, contains a vulnerability that could allow attackers to exploit cross-site scripting. This issue arises when users connect to untrusted remote MCP servers that utilize a malicious redirect URI. If successfully executed, this could enable attackers to interact with the inspector proxy and trigger arbitrary command execution. It is crucial for users to update to version 0.16.6 or later to mitigate the risks associated with this vulnerability.
Affected Version(s)
inspector < 0.16.6