{"repo":"appsecco/vulnerable-mcp-servers-lab","free":true,"listed":false,"github":"https://github.com/appsecco/vulnerable-mcp-servers-lab","clone":"git clone https://github.com/appsecco/vulnerable-mcp-servers-lab.git","description":"A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.","language":"JavaScript","stars":276,"topics":["ai-red-teaming","ai-research","hacking","mcp","mcp-client","mcp-server","pentesting","vulnerable-labs","appsecco","bugbounty"],"license":"MIT","category":"mcp-servers","readme_excerpt":"Vulnerable MCP Servers Lab ========================== This repository contains intentionally vulnerable implementations of Model Context Protocol (MCP) servers (both local and remote). Each server lives in its own folder and includes a dedicated README.md with full details on what it does , how to run it , and how to demonstrate/attack the vulnerability . Do not run any of this outside a controlled lab environment. What this repo is for - Security training / research into common MCP server and tool-integration failure modes. - Hands-on demos of how vulnerable MCP servers can lead to data exposure, instruction injection, supply-chain compromise, and code execution. Safety / lab guidance - Use a disposable VM/container and avoid using real secrets or personal data. - Prefer running on an isolated network ; several servers make outbound network calls. - Treat all tool output and retrieved content as untrusted data . - If you expose any server over HTTP, assume it may be reachable/abused unless you add proper controls. Getting started - Pick a server from the index below. - Open its per-server README and follow the instructions there. - Many servers include a claude config.json snippet intended to be merged into Claude Desktop’s MCP configuration. MCP servers in this repo - Filesystem Workspace Actions (path traversal + code exec) : Tools for reading/writing/listing a “workspace” plus Python execution; vulnerable to naive path joining and unsandboxed code execution. - README: vul","default_branch":null,"files":null,"tree":[],"storefront":"/r/appsecco","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/appsecco/vulnerable-mcp-servers-lab/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}