MCPJam Inspector - Remote Code Execution

MCPJam Inspector - Remote Code Execution

Published 22 Aug 2026Updated 22 Aug 202643 sources
CVSS 0.0 ✓ VERIFIED REFERENCE

What happened

A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.

Affected versions

Unknown product: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
Exploit-DB 52625MCPJam Inspector - Remote Code ExecutionDiamorphine2026-07-07VerifiedPoC-in-GitHub · boroeurnprach/CVE-2026-23744-PoCCVE-2026-23744 - Versions 1.4.2 and earlier of MCPJam inspector are vulnerable to remote code execution (RCE). Because the tool listens on 0.0.0.0 by default, an attacker can trigger the installation and execution of a malicious MCP server by sending a crafted HTTP request. Version 1.4.3 contains a patch for this issue.★ 9boroeurnprach2026-01-20CandidatePoC-in-GitHub · rootdirective-sec/CVE-2026-23744-Lab★ 0rootdirective-sec2026-02-16CandidatePoC-in-GitHub · suljov/CVE-2026-23744-Remote-Code-Execution-POCMCPJam inspector contains a remote code execution★ 11suljov2026-03-21CandidatePoC-in-GitHub · H1sok444/CVE-2026-23744-PoC★ 0H1sok4442026-03-22CandidatePoC-in-GitHub · fckoo/mcpjaminspector-unauth-rceCVE-2026-23744 RCE in MCPJam inspector <= 1.4.2★ 0fckoo2026-03-22CandidatePoC-in-GitHub · FrenzisRed/CVE-2026-23744CVE-2026-23744 - MCPJam inspector Remote-Code-Execution: Proof Of Concept (POC★ 3FrenzisRed2026-03-23CandidatePoC-in-GitHub · InzegoSec/CVE-2026-23744Exploit to MCPJam Inspector <=1.4.2★ 1InzegoSec2026-03-24CandidatePoC-in-GitHub · z4yd3/PoC-CVE-2026-23744Remote Code Execution on MCPJam Inspector <= 1.4.2★ 0z4yd32026-03-25CandidatePoC-in-GitHub · ctzisme/CVE-2026-23744PoC for CVE-2026-23744, demonstrating an unauthenticated RCE in MCPJam Inspector (<= 1.4.2).★ 1ctzisme2026-03-26CandidatePoC-in-GitHub · AhmadF77/CVE-2026-23744python script for exploiting CVE-2026-23744★ 0AhmadF772026-03-27CandidatePoC-in-GitHub · fcjaviergarcia/CVE-2026-23744-POCProof of Concept (PoC) exploit for CVE-2026-23744, a vulnerability affecting MCPJam Inspector that allows remote command execution (RCE) through exposed internal debugging endpoints★ 0fcjaviergarcia2026-03-27CandidatePoC-in-GitHub · 0xg00se/CVE-2026-23744-scriptExploit script for CVE-2026-23744★ 10xg00se2026-03-27CandidatePoC-in-GitHub · d3vn0mi/CVE-2026-23744-POCPython PoC for CVE-2026-23744, unauthenticated RCE in MCP servers via the /api/mcp/connect serverConfig command field (default port 6274)★ 0d3vn0mi2026-03-28CandidatePoC-in-GitHub · CyLock11/CVE-2026-23744CVE-2026-23744 - MCP Connect RCE via Unauthenticated Command Injection★ 0CyLock112026-03-29CandidatePoC-in-GitHub · luiskrnr/exploit-CVE-2026-23744MCPJam Inspector is a local-first development platform for MCP servers. In versions 1.4.2 (and earlier), a RCE flaw lets attackers send crafted HTTP request that installs an MCP server and runs code remotely, because the service listens on 0.0.0.0 (instead of 127.0.0.1) by default.★ 3luiskrnr2026-04-10CandidatePoC-in-GitHub · p1ctur3p3rf3ct/CVE-2026-23744CVE-2026-23744 PoC★ 0p1ctur3p3rf3ct2026-05-31CandidatePoC-in-GitHub · thisisish/HTB-DevHubCVE-2026-23744 RCE + Privilege Escalation★ 4thisisish2026-05-31CandidatePoC-in-GitHub · SrGinebras/CVE-2026-23744-RCE-for-MCPjam-inspector-v1.4.2★ 1SrGinebras2026-05-31CandidatePoC-in-GitHub · sbouabid-sec/CVE-2026-23744-POCCVE-2026-23744 — Proof of concept exploit for an unauthenticated Remote Code Execution vulnerability in MCPJam Inspector <= 1.4.2.★ 0sbouabid-sec2026-05-31CandidatePoC-in-GitHub · Least-Significant-Bit/CVE-2026-23744Remote Code Execution in MCPJam 1.4.2 and older★ 0Least-Significant-Bit2026-05-31CandidatePoC-in-GitHub · afifudinmtop/MCPJam-Inspector-1.4.2-Remote-Code-Execution-CVE-2026-23744★ 0afifudinmtop2026-06-01CandidatePoC-in-GitHub · alisster00/CVE-2026-23744-RCEThis utility was created during research involving MCPJam v1.4.2. The application exposes an API endpoint that accepts a server configuration object. Under certain conditions, insufficient validation may allow unintended command execution.★ 1alisster002026-06-02CandidatePoC-in-GitHub · m2sousa/CVE-2026-23744CVE-2026-23744 Proof-of-concept.★ 0m2sousa2026-06-02CandidatePoC-in-GitHub · MrR0b0t19/CVE-2026-23744-PoC★ 0MrR0b0t192026-06-02CandidatePoC-in-GitHub · jf-gondim/mcp-pwnPoC exploit for CVE-2026-23744 — unauthenticated RCE in MCPJam Inspector via unvalidated serverConfig command injection on /api/mcp/connect, enabling reverse shell as process owner without credentials.★ 0jf-gondim2026-06-03CandidatePoC-in-GitHub · avivyap/CVE-2026-23744CVE-2026-23744★ 0avivyap2026-06-04CandidatePoC-in-GitHub · Dahalsamir/CVE-2026-23744-MCPJAM-RCE-exploitThis Python proof-of-concept targets a vulnerable MCP (Model Context Protocol) service exposed by the target application. The vulnerability allows an attacker to supply arbitrary server configuration parameters through the /api/mcp/connect endpoint.★ 0Dahalsamir2026-06-05CandidatePoC-in-GitHub · keeieb79/CVE-2026-23744-poccve-2026-23744 python exploit★ 0keeieb792026-06-05CandidatePoC-in-GitHub · oryk0/CVE-2026-23744CVE-2026-23744 Reverse shell★ 0oryk02026-06-06CandidatePoC-in-GitHub · kennedy-aikohi/mcpjam-cve-2026-23744-validator★ 0kennedy-aikohi2026-06-09CandidatePoC-in-GitHub · rohit-sundar/cve-2026-23744★ 0rohit-sundar2026-06-14CandidatePoC-in-GitHub · daemoncibsec/mcpExecPOC for CVE-2026-23744 for a python revshell★ 0daemoncibsec2026-06-22CandidatePoC-in-GitHub · timgad794/DevHub-HTB-WalkthroughHack The Box - DevHub Machine Walkthrough (Medium Linux, CVE-2026-23744, Chisel Tunneling, Jupyter, Root Privilege Escalation)★ 0timgad7942026-06-28CandidatePoC-in-GitHub · diamorphine666/CVE-2026-23744-exploitExploit for MCPJam Inspector - Remote Code Execution (CVE-2026-23744)★ 0diamorphine6662026-07-04CandidatePoC-in-GitHub · 0x77FSec/CVE-2026-23744★ 00x77FSec2026-07-10CandidatePoC-in-GitHub · ozcanpng/CVE-2026-23744CVE-2026-23744 MCPJam Inspector unauthenticated RCE PoC★ 1ozcanpng2026-07-11CandidatePoC-in-GitHub · CerberusMrXi/CVE-2026-23744-MCPJam-ExploitA proof-of-concept exploit for CVE-2026-23744 - MCPJam Inspector Remote Code Execution (RCE) vulnerability. This tool demonstrates the security flaw in versions <=1.4.2 and helps security researchers verify patches. For authorized testing and educational purposes only. Includes multiple payload options, command execution, and session management.★ 7CerberusMrXi2026-07-14CandidatePoC-in-GitHub · nullRoot-Red/CVE-2026-23744Proof-of-concept and offensive security research analyzing CVE-2026-23744 (MCPJam Inspector Unauthenticated RCE, Patched in v1.4.3+).★ 0nullRoot-Red2026-07-23CandidatePoC-in-GitHub · Mluex0/CVE-2026-23744-PoCCVE-2026-23744 is an unauthenticated command injection in MCPJam Inspector ≤1.4.2 via /api/mcp/connect. This POC exploits it by sending a crafted JSON payload to execute arbitrary commands, granting a reverse shell with PTY.★ 2Mluex02026-08-10CandidatePoC-in-GitHub · sonnelon/CVE-2026-23744-PoCThe poc of CVE-2026-23744★ 0sonnelon2026-08-10CandidatePoC-in-GitHub · itsC1SCO/mcpjam-to-rootFrom MCPJam Inspector RCE to root — CVE-2026-23744, JupyterLab token disclosure, kernel execution, and OPSMCP privilege escalation★ 0itsC1SCO2026-08-23Candidate