CVE-2025-49596Active Exploitation

MEDIUMCVSS 9.4 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The MCP inspector is a developer tool for testing and debugging MCP servers. Versions of MCP Inspector below 0.14.1 are vulnerable to remote code execution due to lack of authentication between the Inspector client and proxy, allowing unauthenticated requests to launch MCP commands over stdio. Users should immediately upgrade to version 0.14.1 or later to address these vulnerabilities.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 4 classified signals
  • Public PoC is present in monitored signal
  • 6 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 4 signals
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 5d ago at 1 mentions (2026-02-04); latest day: 1
  • 6 total mentions across 6 days

Deep dive

Activity timeline6 mentions / 6d
00111Mentions · 2026-02-04: 1Mentions · 2026-03-20: 1Mentions · 2026-05-19: 1Mentions · 2026-05-25: 1Mentions · 2026-06-16: 1Mentions · 2026-09-21: 1PoC Mentioned / Linked · 2026-05-25: 1Active Exploitation · 2026-02-04: 1Active Exploitation · 2026-03-20: 1Active Exploitation · 2026-05-19: 1Active Exploitation · 2026-05-25: 1Technical Details · 2026-03-20: 1Technical Details · 2026-05-19: 1Technical Details · 2026-05-25: 1Technical Details · 2026-09-21: 102-0403-2005-1905-2506-1609-21
Signal classification2 categories
Active Exploitation
466.7%
Disclosure
233.3%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-02-041
Active Exploitation1
2026-03-201
Active Exploitation1
2026-05-191
Active Exploitation1
2026-05-251
Active Exploitation1
2026-06-161
Disclosure1
2026-09-211
Disclosure1
Full discourse6 posts
  • 森見 | AI・セキュリティ解説@morimi_morimi
    Active Exploitation

    2025年9月には最初の悪意あるMCPパッケージが登場し、 2週間にわたって検出されないままメールデータを 外部に送信し続けていたことが報告されています。 CVE-2025-49596(CVSS 9.4)では 認証なしのMCP Inspectorを経由して 任意コマンド実行が可能だったことも確認されています。

    Post summary

    The passage reports that a malicious MCP package was used to exfiltrate email data for two weeks, while CVE-2025-49596 permits unauthenticated remote command execution.

    110201.1K
    92 followersView on X
  • Petrus@Pete_yes_please
    Active Exploitation

    The documented breach list (April–October 2025): → WhatsApp MCP server: full message history exfiltrated via prompt injection → GitHub MCP server: private repos leaked through crafted tool calls → Anthropic's own desktop dev tool: unauthenticated RCE (CVE-2025-49596) → Fake Postmark MCP server: silently BCC'd all outbound email to attacker → mcp-remote supply chain: arbitrary code execution on client machines Not theoretical. Documented incidents. Real data. http://authzed.com/blog/timeline-mcp-breaches

    Post summary

    The post confirms multiple MCP-related breaches, including CVE‑2025‑49596, with real, documented exploitation but no PoC, tools, or patches. It signals active exploitation in the wild.

    10010134
    55 followersView on X
  • Gagan Suie@gagansuie
    Disclosure

    CVE-2025-49596: RCE in MCP Inspector, scored 9.4, no authentication between client and proxy. CVE-2025-6514: OS command injection in mcp-remote, scored 9.6. Read that trigger. You are compromised by connecting to an untrusted server.

    Post summary

    The text discloses two critical vulnerabilities (CVE-2025-49596 and CVE-2025-6514) in MCP components, providing vulnerability types, CVSS scores, and root cause details without mentioning patches, PoCs, or active exploitation.

    1000068
    206 followersView on X
  • Techgines@nxtgen579255
    Disclosure

    The NSA just published its first formal advisory on MCP security vulnerabilities — the Model Context Protocol running inside ChatGPT, Copilot, Cursor, and VS Code. Key finding: MCP's adoption has outpaced its security model. CVE-2025-49596 . 👇 https://www.techgines.com/post/nsa-mcp-security-vulnerabilities-ai-agent-protocol https://t.co/jNHEfC1wHf

    Post summary

    The NSA released its first formal advisory on MCP security vulnerabilities (CVE-2025-49596), noting that MCP adoption has outpaced its security model, but it does not provide PoC, exploit, patch, or detailed technical specifics.

    0000052
    5 followersView on X
  • Danny Livshits@dannylivshits
    Active Exploitation

    NSA press release: https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4496698/nsa-releases-security-design-considerations-for-ai-driven-automation-leveraging/ NSA CSI PDF: https://www.nsa.gov/Portals/75/documents/Cybersecurity/CSI_MCP_SECURITY.pdf CVE-2025-49596: https://www.oligo.security/blog/critical-rce-vulnerability-in-anthropic-mcp-inspector-cve-2025-49596 GitHub MCP: https://invariantlabs.ai/blog/mcp-github-vulnerability WhatsApp MCP: https://invariantlabs.ai/blog/whatsapp-mcp-exploited NIST overlay timeline: https://www.nextgov.com/artificial-intelligence/2026/05/nist-aims-summer-release-ai-cyber-guidelines/413559/

    Post summary

    The text confirms active exploitation of CVE‑2025‑49596 via WhatsApp and indicates that a PoC exists, but no patch or specific mitigation is provided.

    00000221
    267 followersView on X
  • Lytical Ventures@LyticalVentures
    Active Exploitation

    MCP’s lack of mandatory auth is a "disaster in the making." Thousands of Clawdbot servers are currently exposed to the web, allowing attackers to hijack AI agents via flaws like CVE-2025-49596. Secure your MCP servers now. https://hubs.li/Q040-yQ70 #cybersecurity #cyber #ai https://t.co/71NbmV05Uq

    Post summary

    The tweet highlights that thousands of Clawdbot servers are exposed to CVE-2025-49596, enabling attackers to hijack AI agents, and urges users to secure MCP servers.

    0000073
    150 followersView on X

Explore more