CRITICAL
REC in MCPJam inspector due to HTTP Endpoint exposes
Published Jan 16, 2026
9.8
CRITICALCVSS 3.1
EPSS 67.52%
Description
MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to remote code execution (RCE) vulnerability, which allows an attacker to send a crafted HTTP request that triggers the installation of an MCP server, leading to RCE. Since MCPJam inspector by default listens on 0.0.0.0 instead of 127.0.0.1, an attacker can trigger the RCE remotely via a simple HTTP request. Version 1.4.3 contains a patch.
Affected products
-
- Version <= 1.4.2StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
@mcpjam/inspector
npm
Introduced 0 Fixed 1.4.3
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @mcpjam/inspector | 0 | 1.4.3 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-2859 Advisory
- https://github.com/MCPJam/inspector/commit/e6b9cf9d9e6c9cbec31493b1bdca3a1255fe3e7a x_refsource_MISCPatch
- https://github.com/MCPJam/inspector/security/advisories/GHSA-232v-j27c-5pp6 x_refsource_CONFIRMExploitVendor Advisory
- https://github.com/advisories/GHSA-232v-j27c-5pp6 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-23744
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-2859 | Advisory | |
| https://github.com/MCPJam/inspector/commit/e6b9cf9d9e6c9cbec31493b1bdca3a1255fe3e7a | x_refsource_MISCPatch | |
| https://github.com/MCPJam/inspector/security/advisories/GHSA-232v-j27c-5pp6 | x_refsource_CONFIRMExploitVendor Advisory | |
| https://github.com/advisories/GHSA-232v-j27c-5pp6 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-23744 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jan 16, 2026
Updated Jan 16, 2026
Reserved Jan 15, 2026
Link CVE-2026-23744
CISA Vulnrichment
Updated Jan 16, 2026
ENISA EUVD
EUVD-2026-2859 GHSA-232V-J27C-5PP6 Assigner GitHub_M
Published Jan 16, 2026
Updated Jan 16, 2026
Exploited since n/a
Link EUVD-2026-2859