CVE-2025-49596 describes a critical remote code execution vulnerability in MCP Inspector versions prior to 0.14.1. This flaw, stemming from a lack of authentication between the Inspector client and proxy, allows unauthenticated attackers to execute arbitrary commands via stdio. With a CVSS score of 9.4 (CRITICAL) and a FAUCET Risk Score of 96/100, the vulnerability presents a high risk due to its network-based attack vector and potential for complete compromise of confidentiality, integrity, and availability. While not yet listed in CISA's KEV catalog, public Nuclei templates exist for detection, and the vulnerability has garnered significant community discussion and media coverage, indicating active awareness and potential for future exploitation. Immediate upgrade to version 0.14.1 or later is strongly recommended.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Modelcontextprotocol | Inspector | < 0.14.1CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Anthropic MCP Inspector Remote Code Execution
Jun 17, 2025Anthropic MCP Inspector Remote Code Execution
Jun 17, 2025Anthropic MCP Inspector Remote Code Execution
Jun 17, 2025Anthropic MCP Inspector Remote Code Execution
Jun 17, 2025MCP Inspector proxy server lacks authentication between the Inspector client and proxy
Jun 13, 2025