criticalSecurity flaw UnknownPublish anonymously
MCPJam Inspector RCE (CVE-2026-23744)
by Publish anonymously · 2 days agoviews 0en
PII protected
Personal information such as emails, phone numbers, IDs and access tokens are automatically masked before publication.
CVSS 9.8. MCPJam inspector v1.4.2 and earlier listens on [REDACTED-IP] by default with no authentication. A crafted HTTP request installs a malicious MCP server and executes arbitrary code. Public exploit available. Fixed in v1.4.3.