dotsagent.io
Language:English
CVE-2025-49596

MCP Inspector proxy allowed remote code execution from a browser

MCP Inspector before 0.14.1 ran a local proxy without authentication that a web page could reach, giving code execution on the developer's machine. CVSS 9.4.

What happened

MCP Inspector is a tool developers run to test and debug MCP servers. Versions before 0.14.1 started a local proxy that accepted requests without authentication. A web page open in the developer's browser could reach that proxy and use it to run code on the machine.

The flaw is tracked as CVE-2025-49596 with a CVSS score of 9.4, and version 0.14.1 is the first unaffected release.

Why it worked

Local developer tools often assume that listening on localhost is safe. The browser also runs on localhost, and pages it loads can send requests to local ports, so a local service without authentication can be reached from the web.

What to do

  • Update MCP Inspector to 0.14.1 or later.
  • Require a token on every local proxy and debug server, even when it listens on loopback.
  • Stop the Inspector when you are not actively using it.
  • Test unknown MCP servers inside a container or VM that holds none of your credentials.

Keep control planes off the internetSandbox code and tool execution

Work through the security checklist →

Sources

  1. nvd.nist.gov/vuln/detail/CVE-2025-49596

Independent reference for people who build AI agents. Not affiliated with any vendor named here.

© 2026 DotsAgent · Facts checked October 1, 2026