Feed/CVE-2026-23744
CVE-2026-23744CRITICALCVSS 9.8

CVE-2026-23744

Published Jan 16, 2026·Updated Jun 17, 2026

NVD Description

MCPJam inspector is the local-first development platform for MCP servers. Versions 1.4.2 and earlier are vulnerable to remote code execution (RCE) vulnerability, which allows an attacker to send a crafted HTTP request that triggers the installation of an MCP server, leading to RCE. Since MCPJam inspector by default listens on 0.0.0.0 instead of 127.0.0.1, an attacker can trigger the RCE remotely via a simple HTTP request. Version 1.4.3 contains a patch.

Public Exploits & PoCs38 found

PoC: CVE-2026-23744

A minimal proof-of-concept (PoC) for CVE-2026-23744, demonstrating an unauthenticated RCE in MCPJam Inspector (<= 1.4.2).

1

[POC] GHSA-652q-gvq3-74qv — CVE-2026-23744

Proof-of-concept and offensive security research analyzing CVE-2026-23744 (MCPJam Inspector Unauthenticated RCE, Patched in v1.4.3+).

PoC: mcpjam-to-root

From MCPJam Inspector RCE to root — CVE-2026-23744, JupyterLab token disclosure, kernel execution, and OPSMCP privilege escalation

PoC: CVE-2026-23744-PoC

The poc of CVE-2026-23744

PoC: CVE-2026-23744-PoC

CVE-2026-23744 is an unauthenticated command injection in MCPJam Inspector ≤1.4.2 via /api/mcp/connect. This POC exploits it by sending a crafted JSON payload to execute arbitrary commands, granting a reverse shell with PTY.

PoC: CVE-2026-23744-MCPJam-Exploit

A proof-of-concept exploit for CVE-2026-23744 - MCPJam Inspector Remote Code Execution (RCE) vulnerability. This tool demonstrates the security flaw in versions <=1.4.2 and helps security researchers verify patches. For authorized testing and educational purposes only. Includes multiple payload options, command execution, and session management.

PoC: CVE-2026-23744

CVE-2026-23744 MCPJam Inspector unauthenticated RCE PoC

PoC: CVE-2026-23744-exploit

Exploit for MCPJam Inspector - Remote Code Execution (CVE-2026-23744)

PoC: DevHub-HTB-Walkthrough

Hack The Box - DevHub Machine Walkthrough (Medium Linux, CVE-2026-23744, Chisel Tunneling, Jupyter, Root Privilege Escalation)

PoC: mcpExec

POC for CVE-2026-23744 for a python revshell

PoC: CVE-2026-23744

CVE-2026-23744 Reverse shell

PoC: CVE-2026-23744-poc

cve-2026-23744 python exploit

PoC: CVE-2026-23744-MCPJAM-RCE-exploit

This Python proof-of-concept targets a vulnerable MCP (Model Context Protocol) service exposed by the target application. The vulnerability allows an attacker to supply arbitrary server configuration parameters through the /api/mcp/connect endpoint.

PoC: CVE-2026-23744

CVE-2026-23744

PoC: mcp-pwn

PoC exploit for CVE-2026-23744 — unauthenticated RCE in MCPJam Inspector via unvalidated serverConfig command injection on /api/mcp/connect, enabling reverse shell as process owner without credentials.

PoC: CVE-2026-23744

Proof of Concept exploit for CVE-2026-23744: Remote Code Execution vulnerability in MCPJam Inspector <= 1.4.2

PoC: CVE-2026-23744

CVE-2026-23744 Proof-of-concept.

PoC: CVE-2026-23744-RCE

This utility was created during research involving MCPJam v1.4.2. The application exposes an API endpoint that accepts a server configuration object. Under certain conditions, insufficient validation may allow unintended command execution.

PoC: CVE-2026-23744

Remote Code Execution in MCPJam 1.4.2 and older.

PoC: CVE-2026-23744-POC

CVE-2026-23744 — Proof of concept exploit for an unauthenticated Remote Code Execution vulnerability in MCPJam Inspector <= 1.4.2.

PoC: HTB-DevHub

CVE-2026-23744 RCE + Privilege Escalation

PoC: CVE-2026-23744

CVE-2026-23744 PoC

PoC: DevHub-HackTheBox-ss11

HTB Season 11 — DevHub Writeup Exploiting CVE-2026-23744 (MCPJam Inspector unauthenticated RCE via /api/mcp/connect) to gain initial foothold, then lateral movement through Jupyter Lab token leaked in systemd service file. Stack: nginx · MCPJam Inspector 1.4.2 · Jupyter Lab · OPSMCP (root)

PoC: CVE-2026-23744

CVE-2026-23744 - Versions 1.4.2 and earlier of MCPJam inspector

PoC: kobold

Kobold — HackTheBox Medium writeup: CVE-2026-23744, PrivateBin LFI, Docker group escape to root

PoC: exploit-CVE-2026-23744

MCPJam Inspector is a local-first development platform for MCP servers. In versions 1.4.2 (and earlier), a RCE flaw lets attackers send crafted HTTP request that installs an MCP server and runs code remotely, because the service listens on 0.0.0.0 (instead of 127.0.0.1) by default.

PoC: CVE-2026-23744

CVE-2026-23744 - MCP Connect RCE via Unauthenticated Command Injection

PoC: CVE-2026-23744-POC

Python PoC for CVE-2026-23744, unauthenticated RCE in MCP servers via the /api/mcp/connect serverConfig command field (default port 6274)

PoC: CVE-2026-23744-script

Exploit script for CVE-2026-23744

PoC: CVE-2026-23744-POC

Proof of Concept (PoC) exploit for CVE-2026-23744, a vulnerability affecting MCPJam Inspector that allows remote command execution (RCE) through exposed internal debugging endpoints

PoC: CVE-2026-23744

python script for exploiting CVE-2026-23744

PoC: htb-kobold-writeup

Hack The Box — Kobold writeup. Exploiting CVE-2026-23744 (MCPJam Inspector unauthenticated RCE) to gain initial access as ben, then escaping via Docker group misconfiguration to root.

PoC: PoC-CVE-2026-23744

Remote Code Execution on MCPJam Inspector <= 1.4.2

PoC: CVE-2026-23744

Exploit to MCPJam Inspector <=1.4.2

PoC: CVE-2026-23744

CVE-2026-23744 - MCPJam inspector Remote-Code-Execution: Proof Of Concept (POC

PoC: mcpjaminspector-unauth-rce

CVE-2026-23744 RCE in MCPJam inspector <= 1.4.2

PoC: CVE-2026-23744-Remote-Code-Execution-POC

MCPJam inspector contains a remote code execution

PoC: CVE-2026-23744-PoC

CVE-2026-23744 PoC

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free