Sunday, 13 September 2026
8 agent hacks today 8 vs yesterday (0)

Anthropic MCP Inspector exposed developers to browser-based remote code execution

Oligo Security found that the MCP Inspector developer tool ran a proxy without authentication, so a malicious web page could reach it on localhost and execute commands. Tracked as CVE-2025-49596 with a CVSS score of 9.4.

Occurred 14 April 2025 · Disclosed 1 July 2025 · Record updated 13 September 2026

Impact

Developers running the inspector could be compromised by visiting a web page. Fixed in version 0.14.1 with a session token and origin checks.

Our coverage

Sources

  1. oligo.securityhttps://www.oligo.security/blog/critical-rce-vulnerability-in-anthropic-mcp-inspector-cve-2025-49596
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2025-49596