Vulnerability record · CVE-2026-23744 · published 16 January 2026
CVE-2026-23744: MCPJam inspector unauthenticated RCE via crafted HTTP request
Mcpjam · Inspector
MCPJam inspector versions 1.4.2 and earlier expose a critical function without authentication, allowing a crafted HTTP request to trigger installation of an MCP server and achieve remote code execution. Because the inspector listens on 0.0.0.0 by default rather than localhost, the flaw is reachable over the network, not just locally. Version 1.4.3 patches the issue.
Description
MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to remote code execution (RCE) vulnerability, which allows an attacker to send a crafted HTTP request that triggers the installation of an MCP server, leading to RCE. Since MCPJam inspector by default listens on 0.0.0.0 instead of 127.0.0.1, an attacker can trigger the RCE remotely via a simple HTTP request. Version 1.4.3 contains a patch.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, default network exposure, and public exploit material make this an urgent patch.
What it is
MCPJam inspector versions 1.4.2 and earlier expose a critical function without authentication, allowing a crafted HTTP request to trigger installation of an MCP server and achieve remote code execution. Because the inspector listens on 0.0.0.0 by default rather than localhost, the flaw is reachable over the network, not just locally. Version 1.4.3 patches the issue.
Impact
An unauthenticated attacker gains remote code execution on the host running the inspector, with full compromise of confidentiality, integrity and availability.
Attack surface
Reachable over the network via a simple HTTP request to the inspector service, which binds to 0.0.0.0 by default. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Not listed in CISA KEV, but EPSS is 0.64842 (99.2nd percentile) and the vendor advisory reference is tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade MCPJam inspector to version 1.4.3 or later.
- If immediate upgrade is not possible, bind the inspector to 127.0.0.1 and block external access to its port.
- Restrict network exposure of the inspector service with firewall rules or a reverse proxy requiring authentication.
- Run the inspector with least privilege and isolate it from production systems and sensitive credentials.
- Monitor for unexpected MCP server installations or child processes spawned by the inspector.
Detection
- Alert on HTTP requests to the inspector service that trigger MCP server installation endpoints.
- Monitor for unexpected child processes or package installations spawned by the inspector process.
- Audit network logs for external connections to the inspector port, especially from untrusted sources.
- Track MCP server configuration changes and new server registrations on hosts running the inspector.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2026-23744 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-23744), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.