Vulnerabilities/

MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server

Severity:
High

Description

An XSS flaw exists in the MCP Inspector local development tool when it renders a redirect URL returned by a remote MCP server. If the Inspector connects to an untrusted server, a crafted redirect can inject script into the Inspector context and, via the built-in proxy, be leveraged to trigger arbitrary command execution on the developer machine.

Recommendation

Update the @modelcontextprotocol/inspector package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@modelcontextprotocol/inspector
Anything's wrong? Let us know Last updated on September 26, 2025