Vulnerability library
Security checkJuly 09, 2025

MCP Inspector proxy server lacks authentication between the Inspector client and proxy

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

Versions of MCP Inspector below 0.14.1 are vulnerable to remote code execution due to lack of authentication between the Inspector client and proxy, allowing unauthenticated requests to launch MCP commands over stdio. Users should immediately upgrade to version 0.14.1 or later to address these vulnerabilities.

Recommendation

Update the @modelcontextprotocol/inspector package to the latest compatible version. Followings are version details:

  • Affected version(s): < 0.14.1
  • Patched version(s): 0.14.1

References

Could your website be exposed too?

SmartScanner can check your website for MCP Inspector proxy server lacks authentication between the Inspector client and proxy and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated July 09, 2025