MCP Inspector proxy server lacks authentication between the Inspector client and proxy
Critical severity
GitHub Reviewed
Published
Jun 13, 2025
in
modelcontextprotocol/inspector
•
Updated Jul 9, 2025
Description
Published by the National Vulnerability Database
Jun 13, 2025
Published to the GitHub Advisory Database
Jun 13, 2025
Reviewed
Jun 13, 2025
Last updated
Jul 9, 2025
Versions of MCP Inspector below 0.14.1 are vulnerable to remote code execution due to lack of authentication between the Inspector client and proxy, allowing unauthenticated requests to launch MCP commands over stdio. Users should immediately upgrade to version 0.14.1 or later to address these vulnerabilities.
Credit: Rémy Marot [email protected]
References