Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

MCPJam Inspector <=1.4.2 remote code execution via crafted MCP server install request

MCPJam Inspector, a local-first development platform for MCP servers, contained a remote code execution flaw (CVE-2026-23744) in versions 1.4.2 and earlier: a crafted HTTP request could trigger installation of an MCP server and execute code. Because the tool listened on 0.0.0.0 by default rather than 127.0.0.1, the flaw was exploitable remotely; version 1.4.3 contains a patch.

Disclosed 16 January 2026 · Record updated 13 September 2026

Impact

Unauthenticated attackers able to reach the service could trigger installation of an MCP server and achieve remote code execution on the host running MCPJam Inspector.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-23744