关键漏洞信息 漏洞标题 Potential Command Execution in MCP Inspector via XSS When Connecting to an Untrusted MCP Server 严重性 Severity: High (8.6/10) 影响版本与修复版本 Affected versions: < 0.16.6 Patched versions: 0.16.6 描述 Description: - An XSS issue was reported in the MCP Inspector local development tool when connecting to an untrusted remote MCP server with a malicious redirect URI. This could be leveraged to interact directly with the inspector proxy to trigger arbitrary command execution. - Users are advised to update to 0.16.6 to resolve this issue. 报告者与贡献者 Researchers: - Raymond (Veria Labs) - Gavin Zhong, superboyzjc@gmail.com & Shuyang Wang, swang@obsidiansecurity.com. CVSS v4 基本指标 Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Attack Requirements: None - Privileges Required: None - User Interaction: Active Vulnerable System Impact Metrics: - Confidentiality: High - Integrity: High - Availability: High Subsequent System Impact Metrics: - Confidentiality: None - Integrity: None - Availability: None CVE ID CVE-2025-58444 弱点类型 Weaknesses: CWE-84