THIS WEEK

MCP servers: unauthenticated dev proxies, backdoored packages, and tool poisoning in your agent setup

Risk / Filed 28 Sep 2026 / CVE-2025-49596, CVE-2025-6514, CVE-2025-53109, CVE-2025-53110, CVE-2025-68143, CVE-2025-68144, CVE-2025-68145

mcpagentssupply-chainexposed-api

What: An MCP server is code your agent runs with your user's permissions, and the model obeys whatever text it hands back. Four documented ways this goes wrong:

  • Unauthenticated dev tools. MCP Inspector below 0.14.1 ran a proxy on port 6277 with no auth. It would spawn any command it was told to (CVE-2025-49596, CVSS 9.4). A web page you visit can reach it through 0.0.0.0 or DNS rebinding, so it doesn't have to be port-forwarded. Oligo found instances exposed to the internet. mcp-remote 0.0.5 to 0.1.15 executes a shell command hidden in a malicious server's OAuth authorization_endpoint (CVE-2025-6514, CVSS 9.6).

  • Backdoored packages. postmark-mcp on npm was a copy of the real Postmark server. It behaved for 15 versions, then 1.0.16 added one line that BCC'd every sent email to the attacker. In February 2026 the SANDWORM_MODE worm (typosquats like claud-code and cloude-code) wrote a rogue MCP server into Claude Code, Claude Desktop, Cursor, Continue and Windsurf configs. That server used prompt injection to pull SSH keys, AWS creds, npm tokens and .env files.

  • Tool poisoning and prompt injection. Tool descriptions can hide instructions that the model reads and the UI doesn't show. Invariant Labs used this to make Cursor leak ~/.cursor/mcp.json and ~/.ssh/id_rsa. A server can also change its descriptions after you approve it (a "rug pull"). A README, issue or web page the agent reads works the same way.

  • Over-broad file and shell servers. The official filesystem server could be escaped via symlinks and prefix tricks (CVE-2025-53109/53110). The official git server had path traversal and argument injection (CVE-2025-68143/68144/68145). Prompt injection can reach those bugs, and chained with the filesystem server they give code execution.

Who it hits: You're affected if any of these is true:

  • You ran npx @modelcontextprotocol/inspector (or mcp dev) on an old version, or left it running.

  • Your Claude Code, Cursor or Claude Desktop config launches servers with npx -y <pkg> or uvx <pkg> and no version, so every restart pulls whatever was published last.

  • You have a filesystem server rooted at ~ or /, or a shell or git server, and you auto-approve its tools. It's worse if a fetch, browser or email server sits in the same session.

  • You installed an MCP server from a random npm or PyPI name instead of the vendor's own repo.

Check if you're affected:

# Inspector / MCP HTTP servers listening. Anything on 0.0.0.0, [::] or * is reachable off-box
ss -ltnp | grep -E ':(6274|6277)\b|node|python|uvx'
# Every MCP server your clients will launch. Look for unpinned npx/uvx and names you don't recognise
claude mcp list
jq '.mcpServers, (.projects[]?.mcpServers)' ~/.claude.json 2>/dev/null
jq '.mcpServers' ~/.cursor/mcp.json .mcp.json 2>/dev/null
# Installed versions of the known-bad packages, plus the typosquats
npm ls -g --depth=0 2>/dev/null | grep -Ei 'mcp|inspector|postmark|claud-code|cloude'
uv tool list 2>/dev/null | grep -i mcp; pip list 2>/dev/null | grep -i mcp

Do this:

  1. Kill any Inspector that's running and upgrade. Use npx @modelcontextprotocol/inspector@latest (0.14.1+ needs a session token and checks Origin). Run it only while you're debugging.

  2. Upgrade: mcp-remote to 0.1.16+, server-filesystem to 0.6.3 / 2025.7.01+, mcp-server-git to 2025.12.18+. If postmark-mcp (npm) or any SANDWORM_MODE typosquat turns up, remove it and rotate everything it could reach: mail, SSH keys, cloud and npm tokens, and LLM API keys.

  3. Pin versions in the config (npx -y some-mcp@1.2.3, uvx some-mcp==1.2.3) and install from the vendor's own repo. Re-read the tool descriptions when you bump a version.

  4. Delete servers you don't use. Point filesystem servers at one project directory, never ~. Keep ~/.ssh, ~/.aws and .env outside every allowed root.

  5. Don't auto-approve shell, filesystem-write, git or email tools. Don't put a server that fetches untrusted content (web, issues, mail) in the same session as one that can write or send.

  6. Any MCP server that speaks HTTP should bind to 127.0.0.1 and never be port-forwarded or tunneled without an auth layer in front. Running the agent plus its servers in a container or VM with only the project mounted caps the blast radius.

  7. Confirm: ss shows nothing on 6274/6277, and claude mcp list shows only servers you meant to add, each with a pinned version.

Why this level: Three yes. It's exploited (a backdoored MCP package and a worm writing rogue MCP configs in the wild, plus public PoCs). MCP is in the lab AI stack. The blast radius is your shell, SSH keys and API keys. Reachable is no because most MCP servers are stdio and not exposed. No-friction is no because most paths need you to install a bad package or have the agent read attacker content. If you run an old Inspector or a 0.0.0.0-bound MCP server, treat it as act-tonight.

Sources

How severity is decided. Source file: risks/2026-09-28-mcp-server-risks.md.