{"id":"CVE-2025-58444","aliases":["GHSA-g9hg-qhmf-q45m"],"url":"https://o3.security/vulnerability/CVE-2025-58444","summary":"MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server","details":"An XSS flaw exists in the MCP Inspector local development tool when it renders a redirect URL returned by a remote MCP server. If the Inspector connects to an untrusted server, a crafted redirect can inject script into the Inspector context and, via the built-in proxy, be leveraged to trigger arbitrary command execution on the developer machine. Version 0.16.6 hardens URL handling/validation and prevents script execution.\n\n> Thank you to the following researchers for their reports and contributions:\n> * Raymond (Veria Labs)\n> * Gavin Zhong, <superboyzjc@gmail.com> & Shuyang Wang, <swang@obsidiansecurity.com>.","published":"2025-09-08T21:24:58.821Z","modified":"2026-08-12T03:51:30.508228255Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@modelcontextprotocol/inspector","fixedVersion":"0.16.6"}],"fix":{"url":"https://github.com/modelcontextprotocol/inspector/commit/650f3090d26344a672026b737d81586595bb1f60","label":"modelcontextprotocol/inspector@650f309"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/58xxx/CVE-2025-58444.json"},{"type":"ADVISORY","url":"https://github.com/modelcontextprotocol/inspector/security/advisories/GHSA-g9hg-qhmf-q45m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-58444"},{"type":"FIX","url":"https://github.com/modelcontextprotocol/inspector/commit/650f3090d26344a672026b737d81586595bb1f60"},{"type":"PACKAGE","url":"https://github.com/modelcontextprotocol/inspector"},{"type":"WEB","url":"https://www.npmjs.com/package/@modelcontextprotocol/inspector/v/0.16.6"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:30.508228255Z"}}