Enables AI assistants to interact with Vikunja task management instances, providing full task, project, label, and user management capabilities.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
express-rate-limit: IPv4-mapped IPv6 addresses bypass per-client rate limiting on servers with dual-stack network
uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided
process.env. You'll be asked to provide them before it can run.BULK_MAX_REQUEST_SIZEBULK_MAX_RESPONSE_SIZEBULK_RATE_LIMIT_PER_HOURBULK_RATE_LIMIT_PER_MINUTEBULK_TOOL_TIMEOUTEXPENSIVE_MAX_REQUEST_SIZEEXPENSIVE_MAX_RESPONSE_SIZEEXPENSIVE_RATE_LIMIT_PER_HOUREXPENSIVE_RATE_LIMIT_PER_MINUTEEXPENSIVE_TOOL_TIMEOUTEXPORT_MAX_REQUEST_SIZEEXPORT_MAX_RESPONSE_SIZEEXPORT_RATE_LIMIT_PER_HOUREXPORT_RATE_LIMIT_PER_MINUTEEXPORT_TOOL_TIMEOUTJEST_WORKER_IDMAX_REQUEST_SIZE— 1048576 # Maximum request payload size in bytesMAX_RESPONSE_SIZE— 10485760 # Maximum response size in bytes (default: 10MB)MCP_MODERATE_LIMIT_ENABLEDRATE_LIMIT_PER_HOUR— 1000 # Requests per hour (default: 1000)RATE_LIMIT_PER_MINUTE— 60 # Requests per minute (default: 60)TOOL_TIMEOUTVIKUNJA_API_TOKEN— "": "your-api-token"VIKUNJA_ENABLE_SERVER_SIDE_FILTERINGVIKUNJA_URL— "": "https://your-vikunja-instance.com/api/v1",[](https://m8ven.ai/mcp/4nm1tsu-vikunja-mcp-1605v4)