{"id":"CVE-2025-58444","aliases":["GHSA-g9hg-qhmf-q45m"],"url":"https://o3.security/vulnerability/CVE-2025-58444","summary":"MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server","details":"The MCP inspector is a developer tool for testing and debugging MCP servers. A cross-site scripting issue was reported in versions of the MCP Inspector local development tool prior to 0.16.6 when connecting to untrusted remote MCP servers with a malicious redirect URI. This could be leveraged to interact directly with the inspector proxy to trigger arbitrary command execution. Users are advised to update to 0.16.6 to resolve this issue.","published":"2025-09-08T21:24:58.821Z","modified":"2026-07-15T01:49:18.060010858Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@modelcontextprotocol/inspector","fixedVersion":"0.16.6"}],"fix":{"url":"https://github.com/modelcontextprotocol/inspector/commit/650f3090d26344a672026b737d81586595bb1f60","label":"modelcontextprotocol/inspector@650f309"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/58xxx/CVE-2025-58444.json"},{"type":"ADVISORY","url":"https://github.com/modelcontextprotocol/inspector/security/advisories/GHSA-g9hg-qhmf-q45m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-58444"},{"type":"FIX","url":"https://github.com/modelcontextprotocol/inspector/commit/650f3090d26344a672026b737d81586595bb1f60"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:18.060010858Z"}}