CVE-2025-49596
Last modified
CVE-2025-49596 is a critical-severity vulnerability rated 9.4/10 on the CVSS scale. The MCP inspector is a developer tool for testing and debugging MCP servers. Versions of MCP Inspector below 0.14.1 are vulnerable to remote code execution due to lack of authentication between the Inspector client and proxy, allowing unauthenticated requests to launch MCP commands over stdio. EPSS estimates a 37.03% chance of exploitation in the next 30 days.
Description
The MCP inspector is a developer tool for testing and debugging MCP servers. Versions of MCP Inspector below 0.14.1 are vulnerable to remote code execution due to lack of authentication between the Inspector client and proxy, allowing unauthenticated requests to launch MCP commands over stdio. Users should immediately upgrade to version 0.14.1 or later to address these vulnerabilities.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-49596?
How severe is CVE-2025-49596?
How do I fix CVE-2025-49596?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-49590CryptPad is a collaboration suite. Prior to version 2025.3.0…6.1
- CVE-2025-49591CryptPad is a collaboration suite. Prior to version 2025.3.0…9.1
- CVE-2025-49592n8n is a workflow automation platform. Versions prior to 1.9…5.4
- CVE-2025-49593Portainer Community Edition is a lightweight service deliver…6.8
- CVE-2025-49594XWiki OIDC has various tools to manipulate OpenID Connect pr…9.2
- CVE-2025-49595n8n is a workflow automation platform. Prior to version 1.99…4.9
- CVE-2025-49597handcraftedinthealps goodby-csv is a highly memory efficient…3.9
- CVE-2025-49598conda-forge-ci-setup is a package installed by conda-forge e…4.4
- CVE-2025-49599Huawei EG8141A5 devices through V5R019C00S100, EG8145V5 devi…4.1
- CVE-2025-4960The com.epson.InstallNavi.helper tool, deployed with the EPS…7.8
- CVE-2025-49600In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_verify may accept…4.9
- CVE-2025-49601In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_import_public_key…6.5
Are you affected by CVE-2025-49596?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
