Skip to content

PRP: MCP Inspector CVE-2025-49596 Unauthenticated Remote Code Execution #677

@frkngksl

Description

@frkngksl

In the above checker repository, it only checks for the authorization header in the response. I've verified that this is a valid and reliable indicator on multiple versions. However, I couldn't find any source that explains the real code execution. I'm planning to implement a template plugin that checks the vulnerability in the same way, if you are okay with that. However, I could research further about this to perform exact code execution.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Contributor mainThe main issue a contributor is working on (top of the contribution queue).PRP:Accepted

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions