← Back to browse · API

CVE-2026-23744

Severity
CRITICAL
CVSS
9.8
EPSS
0.45026
Risk score
54.96
CISA KEV
No
PoC
Yes
Published
2026-01-16
Modified
2026-01-16
First seen
2026-08-07
Aliases
EUVD-2026-2859, GHSA-232V-J27C-5PP6
Products
MCPJam:inspector ≤ 1.4.2
Sources
packetstorm e1b15243aca2ad53b47ce4cf|CVE-2026-23744
packetstorm 91e42572019d303b7fcb91f7|CVE-2026-23744
euvd EUVD-2026-2859

Description

MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to remote code execution (RCE) vulnerability, which allows an attacker to send a crafted HTTP request that triggers the installation of an MCP server, leading to RCE. Since MCPJam inspector by default listens on 0.0.0.0 instead of 127.0.0.1, an attacker can trigger the RCE remotely via a simple HTTP request. Version 1.4.3 contains a patch.

References