damn-vulnerable-MCP

themalwarenews/damn-vulnerable-MCP

3.2

If you are the rightful owner of damn-vulnerable-MCP and would like to certify it and/or have it hosted online, please leave a comment on the right or send an email to henry@mcphub.com.

DV-MCP Server is a security training platform with intentional vulnerabilities for educational purposes.

Tools

Functions exposed to the LLM to take actions

read_file

Tool for reading files, vulnerable to path traversal.

execute_command

Tool for executing commands, vulnerable to command injection.

fetch_url

Tool for fetching URLs, vulnerable to SSRF.

get_system_info

Tool for retrieving system information, vulnerable to information disclosure.

Prompts

Interactive templates invoked by user choice

No prompts

Resources

Contextual data attached and managed by the client

No resources