{"id":"GHSA-g9hg-qhmf-q45m","summary":"MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server","details":"An XSS flaw exists in the MCP Inspector local development tool when it renders a redirect URL returned by a remote MCP server. If the Inspector connects to an untrusted server, a crafted redirect can inject script into the Inspector context and, via the built-in proxy, be leveraged to trigger arbitrary command execution on the developer machine. Version 0.16.6 hardens URL handling/validation and prevents script execution.\n\n\u003e Thank you to the following researchers for their reports and contributions:\n\u003e * Raymond (Veria Labs)\n\u003e * Gavin Zhong, \u003csuperboyzjc@gmail.com\u003e & Shuyang Wang, \u003cswang@obsidiansecurity.com\u003e.","aliases":["CVE-2025-58444"],"modified":"2025-09-26T17:07:01Z","published":"2025-09-08T21:14:23Z","database_specific":{"github_reviewed_at":"2025-09-08T21:14:23Z","nvd_published_at":"2025-09-08T22:15:34Z","cwe_ids":["CWE-79","CWE-84","CWE-94"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/modelcontextprotocol/inspector/security/advisories/GHSA-g9hg-qhmf-q45m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-58444"},{"type":"WEB","url":"https://github.com/modelcontextprotocol/inspector/commit/650f3090d26344a672026b737d81586595bb1f60"},{"type":"PACKAGE","url":"https://github.com/modelcontextprotocol/inspector"},{"type":"WEB","url":"https://www.npmjs.com/package/@modelcontextprotocol/inspector/v/0.16.6"}],"affected":[{"package":{"name":"@modelcontextprotocol/inspector","ecosystem":"npm","purl":"pkg:npm/%40modelcontextprotocol/inspector"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.16.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-g9hg-qhmf-q45m/GHSA-g9hg-qhmf-q45m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}