The MCP inspector is a developer tool for testing and debugging MCP servers. A cross-site scripting issue was reported in versions of the MCP Inspector local development tool prior to 0.16.6 when connecting to untrusted remote MCP servers with a malicious redirect URI. This could be leveraged to interact directly with the inspector proxy to trigger arbitrary command execution. Users are advised to update to 0.16.6 to resolve this issue.
Metrics
Affected Vendors & Products
References
History
Mon, 08 Sep 2025 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The MCP inspector is a developer tool for testing and debugging MCP servers. A cross-site scripting issue was reported in versions of the MCP Inspector local development tool prior to 0.16.6 when connecting to untrusted remote MCP servers with a malicious redirect URI. This could be leveraged to interact directly with the inspector proxy to trigger arbitrary command execution. Users are advised to update to 0.16.6 to resolve this issue. | |
Title | MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server | |
Weaknesses | CWE-84 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-08T21:24:58.821Z
Reserved: 2025-09-01T20:03:06.533Z
Link: CVE-2025-58444

No data.

Status : Received
Published: 2025-09-08T22:15:34.247
Modified: 2025-09-08T22:15:34.247
Link: CVE-2025-58444

No data.

No data.