The MCP inspector is a developer tool for testing and debugging MCP servers. A cross-site scripting issue was reported in versions of the MCP Inspector local development tool prior to 0.16.6 when connecting to untrusted remote MCP servers with a malicious redirect URI. This could be leveraged to interact directly with the inspector proxy to trigger arbitrary command execution. Users are advised to update to 0.16.6 to resolve this issue.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Sep 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 08 Sep 2025 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The MCP inspector is a developer tool for testing and debugging MCP servers. A cross-site scripting issue was reported in versions of the MCP Inspector local development tool prior to 0.16.6 when connecting to untrusted remote MCP servers with a malicious redirect URI. This could be leveraged to interact directly with the inspector proxy to trigger arbitrary command execution. Users are advised to update to 0.16.6 to resolve this issue. | |
Title | MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server | |
Weaknesses | CWE-84 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-09-08T21:24:58.821Z
Updated: 2025-09-09T13:31:04.737Z
Reserved: 2025-09-01T20:03:06.533Z
Link: CVE-2025-58444

Updated: 2025-09-09T13:16:37.945Z

Status : Awaiting Analysis
Published: 2025-09-08T22:15:34.247
Modified: 2025-09-09T16:28:43.660
Link: CVE-2025-58444

No data.