Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-49596

70
FAUCET Score

CVE-2025-49596 describes a critical remote code execution vulnerability in MCP Inspector versions prior to 0.14.1. This flaw, stemming from a lack of authentication between the Inspector client and proxy, allows unauthenticated attackers to execute arbitrary commands via stdio. With a CVSS score of 9.4 (CRITICAL) and a FAUCET Risk Score of 96/100, the vulnerability presents a high risk due to its network-based attack vector and potential for complete compromise of confidentiality, integrity, and availability. While not yet listed in CISA's KEV catalog, public Nuclei templates exist for detection, and the vulnerability has garnered significant community discussion and media coverage, indicating active awareness and potential for future exploitation. Immediate upgrade to version 0.14.1 or later is strongly recommended.

Impacted Technologies

VendorProductVersion(s)CPE
ModelcontextprotocolInspector
< 0.14.1CNA affected

CVSS Data

CVSS version used by this source: 4.0

9.4CRITICAL

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
PASSIVE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
HIGH
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
45.00%
Probability of exploitation in next 30 days
EPSS Percentile
98.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Nuclei: CVE-2025-49596 · Sep 8, 2025
This CVE's current EPSS score of 0.4500 is in the 99th percentile among its peer group of 836 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

npmpatch availablevia ghsa
Product: @modelcontextprotocol/inspectorFixed in: 0.14.1
azurevendor investigatingvia llm_extracted
dotnetvendor investigatingvia llm_extracted
langgeniusvendor investigatingvia llm_extracted
phoenix_contactvendor investigatingvia llm_extracted

Vendor Advisories (5)

langgeniusllm-langgenius-813f0e93b7c73ad8CRITICAL

Anthropic MCP Inspector Remote Code Execution

Jun 17, 2025
dotnetllm-dotnet-52579173ceca3f4fCRITICAL

Anthropic MCP Inspector Remote Code Execution

Jun 17, 2025
azurellm-azure-32a8579959b4ae12CRITICAL

Anthropic MCP Inspector Remote Code Execution

Jun 17, 2025
phoenix_contactllm-phoenix_contact-e888cc232fc2cc94CRITICAL

Anthropic MCP Inspector Remote Code Execution

Jun 17, 2025
npmGHSA-7f8r-222p-6f5gcritical

MCP Inspector proxy server lacks authentication between the Inspector client and proxy

Jun 13, 2025

References

github.com / modelcontextprotocol/inspector/commit/50df0e1ec488f3983740b4d28d2a968f12eb8979
github.com / modelcontextprotocol/inspector/security/advisories/GHSA-7f8r-222p-6f5g
thenewstack.io / mcp-vulnerability-exposes-the-ai-untrusted-code-crisis
oligo.security / blog/critical-rce-vulnerability-in-anthropic-mcp-inspector-cve-2025-49596