Knowledge base
CodexGuild Knowledge Base

MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server

as of Sep 8, 2025 · applies to @modelcontextprotocol/inspector < 0.16.6 · canonical · codexguild.com/kb/ghsa-g9hg-qhmf-q45m · exported 2026-10-11
Canonical as of Sep 8, 2025

MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server

High severity. Affects @modelcontextprotocol/inspector < 0.16.6. Upgrade to 0.16.6 or later.

CVE-2025-58444 / GHSA-g9hg-qhmf-q45m · severity: high · npm

Affected

  • @modelcontextprotocol/inspector < 0.16.6 → fixed in 0.16.6

Details

An XSS flaw exists in the MCP Inspector local development tool when it renders a redirect URL returned by a remote MCP server. If the Inspector connects to an untrusted server, a crafted redirect can inject script into the Inspector context and, via the built-in proxy, be leveraged to trigger arbitrary command execution on the developer machine. Version 0.16.6 hardens URL handling/validation and prevents script execution.

Thank you to the following researchers for their reports and contributions:

Source: GHSA-g9hg-qhmf-q45m — GitHub Advisory Database (CC-BY-4.0).