CVE-2025-58444 | modelcontextprotocol inspector up to 0.16.5 cross site scripting (GHSA-g9hg-qhmf-q45m)
A vulnerability categorized as critical has been discovered in modelcontextprotocol inspector up to 0.16.5. This impacts an unknown function. Such manipulation leads to improper neutralization of encoded uri schemes in a web page.
This vulnerability is documented as CVE-2025-58444. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.