
Exploit for CVE-2026-23744, a remote code execution vulnerability in MCPJam Inspector, allowing attackers to execute arbitrary commands via crafted HTTP requests.
MCPJam Inspector is a local-first development platform for MCP servers. In versions 1.4.2 (and earlier), a RCE flaw lets attackers send crafted HTTP request that installs an MCP server and runs code remotely, because the service listens on 0.0.0.0 (instead of 127.0.0.1) by default.
To run: