All verified exploits

CVE-2026-23744 MCPJam Inspector Unauthenticated RCE

Deterministic critical MCPJam Inspector Added cve-verified-cve-2026-23744

Detects MCPJam Inspector at version 1.4.2 or earlier, where the HTTP server binds to all interfaces and exposes the /api/mcp/connect endpoint without authentication. An attacker with network access can send a crafted POST request to execute arbitrary commands on the server.

Is your app exploitable through CVE-2026-23744?

Scan your domain free