@modelcontextprotocol/inspector@0.1.7 vulnerabilities

Model Context Protocol inspector

  • latest version

    0.15.0

  • latest non vulnerable version

  • first published

    7 months ago

  • latest version published

    8 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @modelcontextprotocol/inspector package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • C
    Missing Authentication for Critical Function

    @modelcontextprotocol/inspector is a Model Context Protocol inspector

    Affected versions of this package are vulnerable to Missing Authentication for Critical Function due to a lack of authentication between the client and proxy, an attacker can send unauthenticated requests to the system. This allows them to execute arbitrary commands remotely, leading to a complete compromise of the application.

    How to fix Missing Authentication for Critical Function?

    Upgrade @modelcontextprotocol/inspector to version 0.14.1 or higher.

    <0.14.1