216.73.216.233

CVE-2025-49596

· Published 20/12/2025 20:03 · Modified 21/12/2025 20:39 · Author: AlienVault

Labels: CVE-2025-49596 2025-06-13CVE-2025-49596CWE-306[email protected]

Essential information

Published
20/12/2025 20:03
Modified
21/12/2025 20:39
Author
AlienVault
Creator
AlienVault
CVSS
9.4 CRITICAL (v3) 9.4 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

The MCP inspector is a developer tool for testing and debugging MCP servers. Versions of MCP Inspector below 0.14.1 are vulnerable to remote code execution due to lack of authentication between the Inspector client and proxy, allowing unauthenticated requests to launch MCP commands over stdio. Users should immediately upgrade to version 0.14.1 or later to address these vulnerabilities.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
mcp inspector / mcp inspector cpe:2.3:a:mcp_inspector:mcp_inspector:<0.14.1:*:*:*:*:*:*:*

References