Impact
Based on the description, it is inferred that the attacker does not need authentication to exploit the flaw. MCPJam inspector allows an unauthenticated attacker to send a crafted HTTP request that, due to a missing authentication check for privileged operations (CWE-306), triggers the automatic installation of an MCP server. This operation runs with elevated privileges, giving the attacker full remote code execution on the host. The flaw exists because the service, by default, listens on 0.0.0.0 to any machine that can reach it.
Affected Systems
MCPJam inspector versions 1.4.2 and earlier are affected.
Risk and Exploitability
The vulnerability scores a CVSS base of 9.8 and an EPSS of 44%, indicating a significant likelihood of exploitation. It is not yet listed in the CISA KEV catalog. Based on the description, it is inferred that the attack does not require authentication and can be performed from any network that can reach the HTTP interface, making exposed or open machines at significant risk.
OpenCVE Enrichment
Github GHSA