Burp MCP v2.0.0
Highlights
- Exposes 80+ Burp Suite tools through an MCP stdio bridge.
- Adds UTF-8-safe request handling, stable proxy history indices, and corrected Cookie Jar operations.
- Ships the Bun-native npm bridge and Java 25 Burp extension from one versioned release.
- Adds authenticated localhost transport, MIT licensing, dual-use disclosure, CI, provenance, and staged npm publishing.
Install
- Download
burp-mcp.jarfrom this release and load it in Burp Suite. - Configure your MCP client to run
bunx @nguyenthdat/burpmcpafter the npm stage is approved.
The npm package is staged by GitHub Actions and requires maintainer 2FA approval before becoming public.