Skip to content

v1.0.0

Latest

Choose a tag to compare

@ace-irinco ace-irinco released this 02 May 02:48
4cfe462

Vulnerable MCP Server v1.0.0

Initial release of the Vulnerable MCP Server — an intentionally vulnerable Model Context Protocol server for security testing, education, and CTF challenges.

Features

  • 20+ intentional security vulnerabilities across multiple categories
  • Three transport protocols: stdio, HTTP/SSE, WebSocket
  • 16+ CTF flags across easy, medium, and hard difficulty tiers
  • Full MCP specification compliance (JSON-RPC 2.0)
  • Comprehensive documentation: vulnerability catalog, exploit writeups, cheat sheet, pentest checklist

Vulnerability Categories

  • Path traversal & information disclosure
  • Command injection & SQL injection
  • Server-side template injection (SSTI)
  • Tool poisoning & prompt injection
  • IDOR & broken access control
  • Transport layer attacks
  • Conversation context leakage

Getting Started

See README.md for setup instructions and CHEAT-SHEET.md for a quick exploitation reference.

⚠️ For authorized security testing and educational use only. Do not deploy in production.

Created by IntegSec | Licensed under MIT