CVE-2025-58444

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
08/09/2025
Last modified:
09/09/2025

Description

The MCP inspector is a developer tool for testing and debugging MCP servers. A cross-site scripting issue was reported in versions of the MCP Inspector local development tool prior to 0.16.6 when connecting to untrusted remote MCP servers with a malicious redirect URI. This could be leveraged to interact directly with the inspector proxy to trigger arbitrary command execution. Users are advised to update to 0.16.6 to resolve this issue.