CVE-2025-49596MCP Inspector proxy allowed remote code execution from a browser
MCP Inspector before 0.14.1 ran a local proxy without authentication that a web page could reach, giving code execution on the developer's machine. CVSS 9.4.
What happened
MCP Inspector is a tool developers run to test and debug MCP servers. Versions before 0.14.1 started a local proxy that accepted requests without authentication. A web page open in the developer's browser could reach that proxy and use it to run code on the machine.
The flaw is tracked as CVE-2025-49596 with a CVSS score of 9.4, and version 0.14.1 is the first unaffected release.
Why it worked
Local developer tools often assume that listening on localhost is safe. The browser also runs on localhost, and pages it loads can send requests to local ports, so a local service without authentication can be reached from the web.
What to do
- Update MCP Inspector to 0.14.1 or later.
- Require a token on every local proxy and debug server, even when it listens on loopback.
- Stop the Inspector when you are not actively using it.
- Test unknown MCP servers inside a container or VM that holds none of your credentials.
Keep control planes off the internetSandbox code and tool execution
Supabase MCP agent leaks tokens through a support ticket
EchoLeak: zero-click data theft from Microsoft 365 Copilot
Work through the security checklist →