Vulnerabilities/

MCP Inspector proxy server lacks authentication between the Inspector client and proxy

Severity:
High

Description

Versions of MCP Inspector below 0.14.1 are vulnerable to remote code execution due to lack of authentication between the Inspector client and proxy, allowing unauthenticated requests to launch MCP commands over stdio. Users should immediately upgrade to version 0.14.1 or later to address these vulnerabilities.

Recommendation

Update the @modelcontextprotocol/inspector package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@modelcontextprotocol/inspector
Anything's wrong? Let us know Last updated on July 09, 2025