MCP servers: unauthenticated dev proxies, backdoored packages, and tool poisoning in your agent setup
Risk / Filed 28 Sep 2026 / CVE-2025-49596, CVE-2025-6514, CVE-2025-53109, CVE-2025-53110, CVE-2025-68143, CVE-2025-68144, CVE-2025-68145
mcpagentssupply-chainexposed-api
What: An MCP server is code your agent runs with your user's permissions, and the model obeys whatever text it hands back. Four documented ways this goes wrong:
-
Unauthenticated dev tools. MCP Inspector below 0.14.1 ran a proxy on port 6277 with no auth. It would spawn any command it was told to (CVE-2025-49596, CVSS 9.4). A web page you visit can reach it through
0.0.0.0or DNS rebinding, so it doesn't have to be port-forwarded. Oligo found instances exposed to the internet. mcp-remote 0.0.5 to 0.1.15 executes a shell command hidden in a malicious server's OAuthauthorization_endpoint(CVE-2025-6514, CVSS 9.6). -
Backdoored packages.
postmark-mcpon npm was a copy of the real Postmark server. It behaved for 15 versions, then 1.0.16 added one line that BCC'd every sent email to the attacker. In February 2026 the SANDWORM_MODE worm (typosquats likeclaud-codeandcloude-code) wrote a rogue MCP server into Claude Code, Claude Desktop, Cursor, Continue and Windsurf configs. That server used prompt injection to pull SSH keys, AWS creds, npm tokens and.envfiles. -
Tool poisoning and prompt injection. Tool descriptions can hide instructions that the model reads and the UI doesn't show. Invariant Labs used this to make Cursor leak
~/.cursor/mcp.jsonand~/.ssh/id_rsa. A server can also change its descriptions after you approve it (a "rug pull"). A README, issue or web page the agent reads works the same way. -
Over-broad file and shell servers. The official filesystem server could be escaped via symlinks and prefix tricks (CVE-2025-53109/53110). The official git server had path traversal and argument injection (CVE-2025-68143/68144/68145). Prompt injection can reach those bugs, and chained with the filesystem server they give code execution.
Who it hits: You're affected if any of these is true:
-
You ran
npx @modelcontextprotocol/inspector(ormcp dev) on an old version, or left it running. -
Your Claude Code, Cursor or Claude Desktop config launches servers with
npx -y <pkg>oruvx <pkg>and no version, so every restart pulls whatever was published last. -
You have a filesystem server rooted at
~or/, or a shell or git server, and you auto-approve its tools. It's worse if a fetch, browser or email server sits in the same session. -
You installed an MCP server from a random npm or PyPI name instead of the vendor's own repo.
Check if you're affected:
# Inspector / MCP HTTP servers listening. Anything on 0.0.0.0, [::] or * is reachable off-box
ss -ltnp | grep -E ':(6274|6277)\b|node|python|uvx'
# Every MCP server your clients will launch. Look for unpinned npx/uvx and names you don't recognise
claude mcp list
jq '.mcpServers, (.projects[]?.mcpServers)' ~/.claude.json 2>/dev/null
jq '.mcpServers' ~/.cursor/mcp.json .mcp.json 2>/dev/null
# Installed versions of the known-bad packages, plus the typosquats
npm ls -g --depth=0 2>/dev/null | grep -Ei 'mcp|inspector|postmark|claud-code|cloude'
uv tool list 2>/dev/null | grep -i mcp; pip list 2>/dev/null | grep -i mcp
Do this:
-
Kill any Inspector that's running and upgrade. Use
npx @modelcontextprotocol/inspector@latest(0.14.1+ needs a session token and checks Origin). Run it only while you're debugging. -
Upgrade: mcp-remote to 0.1.16+, server-filesystem to 0.6.3 / 2025.7.01+, mcp-server-git to 2025.12.18+. If
postmark-mcp(npm) or any SANDWORM_MODE typosquat turns up, remove it and rotate everything it could reach: mail, SSH keys, cloud and npm tokens, and LLM API keys. -
Pin versions in the config (
npx -y some-mcp@1.2.3,uvx some-mcp==1.2.3) and install from the vendor's own repo. Re-read the tool descriptions when you bump a version. -
Delete servers you don't use. Point filesystem servers at one project directory, never
~. Keep~/.ssh,~/.awsand.envoutside every allowed root. -
Don't auto-approve shell, filesystem-write, git or email tools. Don't put a server that fetches untrusted content (web, issues, mail) in the same session as one that can write or send.
-
Any MCP server that speaks HTTP should bind to
127.0.0.1and never be port-forwarded or tunneled without an auth layer in front. Running the agent plus its servers in a container or VM with only the project mounted caps the blast radius. -
Confirm:
ssshows nothing on 6274/6277, andclaude mcp listshows only servers you meant to add, each with a pinned version.
Why this level: Three yes. It's exploited (a backdoored MCP package and a worm writing rogue MCP configs in the wild, plus public PoCs). MCP is in the lab AI stack. The blast radius is your shell, SSH keys and API keys. Reachable is no because most MCP servers are stdio and not exposed. No-friction is no because most paths need you to install a bad package or have the agent read attacker content. If you run an old Inspector or a 0.0.0.0-bound MCP server, treat it as act-tonight.
Sources
- GHSA-7f8r-222p-6f5g: MCP Inspector unauthenticated RCE (CVE-2025-49596), fixed in 0.14.1
- Oligo: Inspector proxy on 6277 hit from a browser via 0.0.0.0 / DNS rebinding; exposed instances found
- GHSA-6xpm-ggf7-wc3p: mcp-remote OS command injection (CVE-2025-6514), fixed in 0.1.16
- GHSA-q66q-fx2p-7w4m: server-filesystem symlink escape (CVE-2025-53109)
- Cymulate: EscapeRoute (CVE-2025-53109 / CVE-2025-53110), filesystem server sandbox escape
- The Hacker News: mcp-server-git CVE-2025-68143/68144/68145, prompt-injection-reachable, chained to RCE
- Postmark: malicious postmark-mcp npm package (backdoor from 1.0.16)
- The Register: postmark-mcp BCC'd every email to the attacker (Koi Security)
- The Hacker News: SANDWORM_MODE npm worm injects a rogue MCP server into Claude Code, Cursor, Windsurf configs (Feb 2026)
- Invariant Labs: tool poisoning, rug pulls and shadowing via MCP tool descriptions
- Claude Code docs: MCP config locations, claude mcp list, prompt-injection warning
How severity is decided. Source file: risks/2026-09-28-mcp-server-risks.md.