Description
The MCP inspector is a developer tool for testing and debugging MCP servers. A cross-site scripting issue was reported in versions of the MCP Inspector local development tool prior to 0.16.6 when connecting to untrusted remote MCP servers with a malicious redirect URI. This could be leveraged to interact directly with the inspector proxy to trigger arbitrary command execution. Users are advised to update to 0.16.6 to resolve this issue.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27271 | MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server |
Github GHSA |
GHSA-g9hg-qhmf-q45m | MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server |
References
History
Tue, 09 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Sep 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The MCP inspector is a developer tool for testing and debugging MCP servers. A cross-site scripting issue was reported in versions of the MCP Inspector local development tool prior to 0.16.6 when connecting to untrusted remote MCP servers with a malicious redirect URI. This could be leveraged to interact directly with the inspector proxy to trigger arbitrary command execution. Users are advised to update to 0.16.6 to resolve this issue. | |
| Title | MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server | |
| Weaknesses | CWE-84 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-09T13:31:04.737Z
Reserved: 2025-09-01T20:03:06.533Z
Link: CVE-2025-58444
Updated: 2025-09-09T13:16:37.945Z
Status : Deferred
Published: 2025-09-08T22:15:34.247
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-58444
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA