Skip to content

Hide Navigation Hide TOC

MCP Inspector Unauthenticated Proxy stdio Command Execution (CVE-2025-49596) - ATR-2026-02021 (0852f41d-e5fa-5066-8698-82a82c70d673)

Detects exploitation of CVE-2025-49596 (CVSS 9.4), the unauthenticated proxy RCE in Anthropic's MCP Inspector (versions < 0.14.1) reported by Oligo Security. The Inspector proxy listens on 0.0.0.0:6277 and exposes an /sse endpoint that spawns an MCP server over stdio using attacker-controlled transportType, command, and args query parameters — with no authentication or origin check. A malicious public web page (or a DNS-rebinding origin that resolves to 127.0.0.1/0.0.0.0) can issue a cross-site fetch to http://0.0.0.0:6277/sse?transportType=stdio&command=&args= and achieve arbitrary OS command execution on the developer's machine. This rule fires on the concrete request signature — the :6277/sse endpoint carrying transportType=stdio together with a command= parameter — not on prose that merely names the CVE. Patched in 0.14.1 by adding session-token auth and Origin verification.

Cluster A Galaxy A Cluster B Galaxy B Level
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern MCP Inspector Unauthenticated Proxy stdio Command Execution (CVE-2025-49596) - ATR-2026-02021 (0852f41d-e5fa-5066-8698-82a82c70d673) Agent Threat Rules 1
LLM Plugin Compromise (adbb0dd5-ff66-4b2f-869f-bfb3fdb45fc8) MITRE ATLAS Attack Pattern MCP Inspector Unauthenticated Proxy stdio Command Execution (CVE-2025-49596) - ATR-2026-02021 (0852f41d-e5fa-5066-8698-82a82c70d673) Agent Threat Rules 1
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 2