Critical RCE Vulnerability in Anthropic MCP Inspector – CVE-2025-49596
oligo.security
oligo.security
The 0.0.0.0-day vulnerability is a 19-year old unpatched bug that exists on many browsers [0] that no-one cared about fixing and it's used to infiltrate local services on the user's machine by visiting any website that fetches from https://0.0.0.0/....
So it is really is not a good idea to have MCP servers and proxies running all over the place on your machine and then you get pwned by going to some random website.
Additionally, including data exfiltration, RCEs, and data leakages the "Model Context Protocol" is really one of the worst standards that has ever been designed.
[0] https://www.oligo.security/blog/0-0-0-0-day-exploiting-local...