Description
An XSS flaw exists in the MCP Inspector local development tool when it renders a redirect URL returned by a remote MCP server. If the Inspector connects to an untrusted server, a crafted redirect can inject script into the Inspector context and, via the built-in proxy, be leveraged to trigger arbitrary command execution on the developer machine.
Recommendation
Update the @modelcontextprotocol/inspector package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.16.6
- Patched version(s): 0.16.6
References
Could your website be exposed too?
SmartScanner can check your website for MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Lobe Chat Desktop vulnerable to Remote Code Execution via XSS in Chat Messages - CVE-2025-59417
- Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE - CVE-2025-64495
- MCP Inspector proxy server lacks authentication between the Inspector client and proxy - CVE-2025-49596
- [Eclipse Theia] Arbitrary Command Execution via Untrusted Workspace Task Definitions - @theia/task - CVE-2026-44691


