Description
Versions of MCP Inspector below 0.14.1 are vulnerable to remote code execution due to lack of authentication between the Inspector client and proxy, allowing unauthenticated requests to launch MCP commands over stdio. Users should immediately upgrade to version 0.14.1 or later to address these vulnerabilities.
Recommendation
Update the @modelcontextprotocol/inspector package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.14.1
- Patched version(s): 0.14.1
References
Could your website be exposed too?
SmartScanner can check your website for MCP Inspector proxy server lacks authentication between the Inspector client and proxy and gives you actionable findings to investigate.
Start a free scanRelated Issues
- MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server - CVE-2025-58444
- Microsoft Playwright MCP Server vulnerable to DNS Rebinding Attack; Allows Attackers Access to All Server Tools - CVE-2025-9611
- @andrea9293/mcp-documentation-server: Web UI API binds to all interfaces without authentication by default - CVE-2026-54504
- Nu Html Checker (vnu) contains a Server-Side Request Forgery (SSRF) vulnerability - CVE-2025-15104


