peter bassill · operator
$ cve CVE-2026-23744 JSON

CVE-2026-23744 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 67.5% (pctl 99)

Patch early

A public exploit exists.

Description

MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to remote code execution (RCE) vulnerability, which allows an attacker to send a crafted HTTP request that triggers the installation of an MCP server, leading to RCE. Since MCPJam inspector by default listens on 0.0.0.0 instead of 127.0.0.1, an attacker can trigger the RCE remotely via a simple HTTP request. Version 1.4.3 contains a patch.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS67.52% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-306
On CISA KEVno
Public exploityes
Published2026-01-16
Last modified2026-06-17

Affected (1)

VendorProduct
mcpjaminspector

Public exploits

SourceTitleDate
exploit-dbMCPJam Inspector - Remote Code Execution2026-07-07

References

→ the Explorer  ·  watch your stack  ·  NVD