ZeroHour

CVE-2026-23744

PoC niche

Unauthenticated RCE in MCPJam Inspector via crafted HTTP requests

CVSS 3.1
9.8 critical
EPSS
65%p99
Published
()
Modified
AI analysis

MCPJam inspector versions 1.4.2 and earlier are vulnerable to unauthenticated remote code execution (CWE-306): a crafted HTTP request triggers the installation of an MCP server, which results in arbitrary code execution on the host running the inspector. Because the tool binds to 0.0.0.0 by default instead of 127.0.0.1, any machine that can reach the listening port — typically other hosts on the local network, or the internet if port-forwarded — can exploit it with no credentials and no user interaction. A successful attack gives the attacker code execution in the context of the inspector process on developer workstations or servers where the tool is running. Anyone running MCPJam inspector 1.4.2 or earlier is affected, with exposure concentrated among developers working with MCP servers locally. No confirmed in-the-wild exploitation is reported (not in CISA KEV), but a public PoC reference exists and EPSS assigns a 65.8% probability of exploitation within 30 days, making rapid patching advisable.

What to do: Upgrade to MCPJam inspector 1.4.3 or later immediately; until patched, bind the tool to 127.0.0.1 or firewall its listening port so only trusted hosts can reach it. Because the flaw requires no authentication, treat any host that ran 1.4.2 or earlier while the port was reachable from untrusted networks as potentially compromised and review for unexpected MCP server installs or process execution.

Affected
mcpjam inspector1.4.2 and earlier (fixed in 1.4.3)
Estimated exposure
nichelikely low thousands of installations at most (no public install counts) — No public install counts exist in the data, so this is based on deployment patterns: MCPJam inspector is a niche, local-first developer tool for the MCP ecosystem that is typically launched ad hoc on individual workstations, and only…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to remote code execution (RCE) vulnerability, which allows an attacker to send a crafted HTTP request that triggers the installation of an MCP server, leading to RCE. Since MCPJam inspector by default listens on 0.0.0.0 instead of 127.0.0.1, an attacker can trigger the RCE remotely via a simple HTTP request. Version 1.4.3 contains a patch.

Vendors
mcpjam
Products
inspector
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

Metasploit Wrap Up: This One Goes to Sixteen!

Metasploit adds 16 modules including 10 exploits, five covering CISA KEV vulnerabilities in Cisco, SonicWall, PaperCut, JetBrains and Langflow.

Rapid7's weekly Metasploit update ships 16 new modules, 10 of them exploit modules, with five targeting CISA KEV entries. New exploits cover Cisco Secure Firewall Management Center auth bypass (CVE-2026-20079), a SonicWall SMA1000 SSRF-to-root RCE chain (CVE-2026-83548/CVE-2026-83549), JetBrains TeamCity deserialization RCE (CVE-2026-63077), PaperCut NG/MF chain (CVE-2026-81578/CVE-2026-82078), and Langflow authenticated RCE (CVE-2026-19295). The SonicWall and PaperCut chains were reported as actively exploited zero-days, and a new ESC8 relay module exploits CVE-2026-20929 against AD CS Web Enrollment.

Rapid7 Blog · 4d agoTools in the wildCVE-2025-66516CVE-2025-54988CVE-2026-20929+8 CVEs1