Visiting a web page could compromise developers running MCP Inspector
Anthropic's debugging tool listened without authentication. A malicious site could reach it on localhost and run commands.
2 Jul 2025
Oligo Security found that the MCP Inspector developer tool ran a proxy without authentication, so a malicious web page could reach it on localhost and execute commands. Tracked as CVE-2025-49596 with a CVSS score of 9.4.
Occurred 14 April 2025 · Disclosed 1 July 2025 · Record updated 13 September 2026
Developers running the inspector could be compromised by visiting a web page. Fixed in version 0.14.1 with a session token and origin checks.
Anthropic's debugging tool listened without authentication. A malicious site could reach it on localhost and run commands.
2 Jul 2025