Vulnerable MCP Server

Created By
evrenyala year ago
Vulnerable MCP Server
Overview

What is Vulnerable MCP Server?

The Vulnerable MCP Server is an intentionally insecure application designed for security research, specifically to test SQL Injection (SQLi) and Remote Code Execution (RCE) vulnerabilities.

How to use Vulnerable MCP Server?

To use the Vulnerable MCP Server, clone the repository from GitHub, navigate to the project directory, and run the application using Docker. Ensure to use it only in isolated environments or for research purposes.

Key features of Vulnerable MCP Server?

  • LLM-based decision logic for routing commands (SQL or CLI)
  • Native execution of SQL and terminal commands
  • Auto-initializing SQLite database with sample data
  • Simple, pluggable JSON-RPC methods
  • Designed to be vulnerable for testing purposes

Use cases of Vulnerable MCP Server?

  1. Testing SQL Injection vulnerabilities in a controlled environment.
  2. Conducting research on Remote Code Execution vulnerabilities.
  3. Educational purposes in Capture The Flag (CTF) competitions.

FAQ from Vulnerable MCP Server?

  • Is this server safe to use in production?

No! This server is intentionally insecure and should not be used in production environments.

  • Can I use this for learning about security vulnerabilities?

Yes! This server is designed for educational purposes and security research.

Project Info
Created At
a year ago
Updated At
a year ago
Author Name
evrenyal
Star
0
Language
Python
License
-
Category
security

Recommend Servers

View All
//beforeyouship — LLM Cost Modeling From Your Editor
@Indiegoing

Query realistic LLM cost models without leaving your editor. beforeyouship models the **true monthly cost** of an LLM app architecture — retries, prompt caching, batch discounts, infra overhead, and 3×/10× growth — across GPT-5.x, Claude, Gemini, DeepSeek, and more. Not a token calculator: a planning tool for the design phase, before you commit to a stack. **No API key needed to try it** — demo mode covers the six free-tier models. A Pro key from [beforeyouship.dev](https://beforeyouship.dev) unlocks the full 18-model catalog. ## What you can ask - "How much will a RAG chatbot cost at 10,000 requests/day?" - "Compare Claude Haiku vs Gemini Flash pricing for my workload" - "What's the cheapest model for a multi-step agent at scale?" - "Show me current per-token prices for Anthropic models" ## Tools ### `estimate_cost` Full cost model for an architecture at a given usage level. Returns Naive / Realistic / Worst Case monthly cost per model, 3×/10× growth scenarios, and an opinionated recommendation with reasoning. ### `get_model_prices` Current per-1M-token pricing — input, output, cached input, batch — with context windows and staleness metadata. ### `list_archetypes` Seven preset architecture patterns (simple chatbot, chatbot with history, RAG pipeline, multi-model router, coding assistant, document processor, multi-step agent) used as starting points for estimates. ## Setup **Claude Code:** ​```bash claude mcp add --transport http beforeyouship https://beforeyouship.dev/api/mcp ​``` **Cursor / other clients** — add a remote server: ​```json { "mcpServers": { "beforeyouship": { "type": "streamable-http", "url": "https://beforeyouship.dev/api/mcp" } } } ​``` Add an `Authorization: Bearer bys_...` header with a Pro key for the full catalog. ## Try it > Estimate the monthly cost of a RAG pipeline at 10,000 requests/day

a day ago
Mnemom

a day ago