{"repo":"PawelKozy/mcp-breach-to-fix-labs","free":true,"listed":false,"github":"https://github.com/PawelKozy/mcp-breach-to-fix-labs","clone":"git clone https://github.com/PawelKozy/mcp-breach-to-fix-labs.git","description":"Hands-on MCP security lab: 10 real incidents reproduced with vulnerable/secure MCP servers, pytest regressions, and Claude/Cursor battle-tested exploit walkthroughs","language":"Python","stars":89,"topics":[],"license":null,"category":"mcp-servers","readme_excerpt":"# MCP Breach-to-Fix Labs Hands-on lab of ten Model Context Protocol (MCP) challenges reproduced from real CVEs and public incident reports. I've run every exploit end-to-end with Cursor/Claude, so the steps aren't theoretical—they're the exact tool calls the assistants followed. Every scenario ships in two modes: - Vulnerable - intentionally exploitable implementation you can reproduce end-to-end in Cursor/Claude Desktop. - Secure - hardened implementation with defense-in-depth controls that block the attack. These labs were fully battle-tested with Claude/Cursor, ensuring the exact exploit/mitigation flow is reproducible. Each challenge includes Docker services, FastMCP servers, fixtures, and screenshots that prove the exploit really runs—no theoretical write-ups. Challenge Catalog # Challenge Scenario Highlights --- ----------- --------------------- 01 CRM Confused Deputy Shared CRM token + predictable IDs leak other tenants’ records. Secure version scopes credentials per tenant. 02 Filesystem Prefix Bypass (CVE-2025-53110) Naive startswith path check vs. canonical path enforcement. 03 Hidden Instructions in Tool Responses Malicious tool responses inject hidden instructions that redirect WhatsApp messages; secure build sanitizes responses. 04 Xata Read-Only Bypass Multi-statement SELECT; attacker appends DELETE to mutate data. Secure build uses sqlparse to enforce single statements. 05 News Prompt Exfiltration Malicious article tells the agent to dump config + email it back","default_branch":null,"files":null,"tree":[],"storefront":"/r/PawelKozy","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/PawelKozy/mcp-breach-to-fix-labs/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}