CVE-2025-49596
MCP Inspector proxy server lacks authentication between the Inspector client and proxy
EPSS 2.6%
描述
Versions of MCP Inspector below 0.14.1 are vulnerable to remote code execution due to lack of authentication between the Inspector client and proxy, allowing unauthenticated requests to launch MCP commands over stdio. Users should immediately upgrade to version 0.14.1 or later to address these vulnerabilities. Credit: Rémy Marot <[email protected]>
如何修補 CVE-2025-49596
要修補 CVE-2025-49596,請將受影響套件升級到下列已修補版本。
- npm/@modelcontextprotocol/inspector—升級至 0.14.1 或更新版本
CVE-2025-49596 正在被利用嗎?
低 — EPSS 為 2.6%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 0.14.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |