GHSA-g9hg-qhmf-q45m
MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server
Quick fix
GHSA-g9hg-qhmf-q45m — @modelcontextprotocol/inspector: upgrade to the fixed version with the command below.
npm install @modelcontextprotocol/inspector@0.16.6Details
An XSS flaw exists in the MCP Inspector local development tool when it renders a redirect URL returned by a remote MCP server. If the Inspector connects to an untrusted server, a crafted redirect can inject script into the Inspector context and, via the built-in proxy, be leveraged to trigger arbitrary command execution on the developer machine. Version 0.16.6 hardens URL handling/validation and prevents script execution.
> Thank you to the following researchers for their reports and contributions: > * Raymond (Veria Labs) > * Gavin Zhong, <superboyzjc@gmail.com> & Shuyang Wang, <swang@obsidiansecurity.com>.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 0.16.6npm install @modelcontextprotocol/inspector@0.16.6References
- https://github.com/modelcontextprotocol/inspector/security/advisories/GHSA-g9hg-qhmf-q45m[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-58444[ADVISORY]
- https://github.com/modelcontextprotocol/inspector/commit/650f3090d26344a672026b737d81586595bb1f60[WEB]
- https://github.com/modelcontextprotocol/inspector[PACKAGE]
- https://www.npmjs.com/package/@modelcontextprotocol/inspector/v/0.16.6[WEB]