Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27271 | MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server |
Github GHSA |
GHSA-g9hg-qhmf-q45m | MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server |
Tue, 09 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Sep 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The MCP inspector is a developer tool for testing and debugging MCP servers. A cross-site scripting issue was reported in versions of the MCP Inspector local development tool prior to 0.16.6 when connecting to untrusted remote MCP servers with a malicious redirect URI. This could be leveraged to interact directly with the inspector proxy to trigger arbitrary command execution. Users are advised to update to 0.16.6 to resolve this issue. | |
| Title | MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server | |
| Weaknesses | CWE-84 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-09T13:31:04.737Z
Reserved: 2025-09-01T20:03:06.533Z
Link: CVE-2025-58444
Updated: 2025-09-09T13:16:37.945Z
Status : Deferred
Published: 2025-09-08T22:15:34.247
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-58444
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA