Threat · curated 17 Jul 2026
CVE-2026-23744 - CVE Details, Severity, and Analysis | Strobes VI
First reported strobes.co
Coverage timeline
Single-source advisory — first reported, latest, and curated coincide.
Why it matters
CVE-2026-23744 lets attackers achieve unauthenticated remote code execution against a widely used MCP development tool over the network, exposing developer machines running AI agent tooling to full compromise.
CVE-2026-23744 is a critical (CVSS 9.8) remote code execution vulnerability in MCPJam Inspector versions 1.4.2 and earlier, a local-first development platform for MCP servers. Because the tool binds to 0.0.0.0 and its /api/mcp/connect endpoint extracts command and args without security checks, an attacker can send a crafted, unauthenticated HTTP request to trigger arbitrary command execution with no user interaction; public PoCs and vendor patches are available.