MCP Hub
Back to servers

vulnerable-mcp-servers-lab

A collection of intentionally vulnerable MCP servers designed for security training and labs to demonstrate risks like path traversal, RCE, and prompt injection.

Stars
85
Forks
15
Updated
Dec 18, 2025
Validated
Jan 9, 2026

Vulnerable MCP Servers Lab

This repository contains intentionally vulnerable implementations of Model Context Protocol (MCP) servers (both local and remote). Each server lives in its own folder and includes a dedicated README.md with full details on what it does, how to run it, and how to demonstrate/attack the vulnerability.

Do not run any of this outside a controlled lab environment.

What this repo is for

  • Security training / research into common MCP server and tool-integration failure modes.
  • Hands-on demos of how vulnerable MCP servers can lead to data exposure, instruction injection, supply-chain compromise, and code execution.

Safety / lab guidance

  • Use a disposable VM/container and avoid using real secrets or personal data.
  • Prefer running on an isolated network; several servers make outbound network calls.
  • Treat all tool output and retrieved content as untrusted data.
  • If you expose any server over HTTP, assume it may be reachable/abused unless you add proper controls.

Getting started

  • Pick a server from the index below.
  • Open its per-server README and follow the instructions there.
  • Many servers include a claude_config.json snippet intended to be merged into Claude Desktop’s MCP configuration.

MCP servers in this repo

About Appsecco

Appsecco is a cybersecurity company specializing in product security testing, penetration testing, and security assessments. We hack SaaS products, AI Agents, MCP Servers and cloud/K8s infrastructure like attackers do, focusing on pragmatic, high-signal outcomes for real-world systems.

This lab repository exists to support security research and hands-on training for pentesters, who are on their journey to becoming AI Red Teamers, around MCP server vulnerabilities and the risks of integrating untrusted tools and untrusted content into AI agent workflows.

Contact

License

See LICENSE.

Links to Appsecco Resources

Reviews

No reviews yet

Sign in to write a review

vulnerable-mcp-servers-lab — MCP Server | MCP Hub