Web search using free multi-engine search (NO API KEYS REQUIRED) — Supports Bing, Baidu, DuckDuckGo, Brave, Exa, Github, Juejin, and CSDN.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
process.env. You'll be asked to provide them before it can run.ALLOWED_SEARCH_ENGINES— empty (all available) Comma-separated engine names Limit which search engines can be used; if the default engine is not in this list, the first allowed engine becomes the defaultCORS_ORIGIN— Any valid origin CORS origin configurationDEFAULT_SEARCH_ENGINE— duckduckgo ENABLE_CORS=true npx open-websearch@latestENABLE_CORS— DEFAULT_SEARCH_ENGINE=duckduckgo =true npx open-websearch@latestFAKE_IP_CIDRS— For Clash fake-ip / TUN setups, configure synthetic DNS ranges with (for example 198.18.0.0/15)FETCH_WEB_INSECURE_TLS— false true, false Disable TLS certificate verification for fetchWebContent only. Use only when a target site has a broken certificate chainMODE— set =stdio && set DEFAULT_SEARCH_ENGINE=duckduckgo && npx open-websearch@latestOPEN_WEBSEARCH_DAEMON_ACTION_TIMEOUT_MSOPEN_WEBSEARCH_DAEMON_DISCOVERY_TIMEOUT_MSOPEN_WEBSEARCH_DAEMON_HOSTOPEN_WEBSEARCH_DAEMON_PORTOPEN_WEBSEARCH_DAEMON_TIMEOUT_MSOPEN_WEBSEARCH_DAEMON_URLOPEN_WEBSEARCH_DEBUGOPEN_WEBSEARCH_QUIET_STARTUPPLAYWRIGHT_HEADLESS— true true, false Whether Playwright Chromium runs in headless modePLAYWRIGHT_NAVIGATION_TIMEOUT_MS— 20000 Positive integer Timeout for Playwright navigation and Bing result waitsPLAYWRIGHT_PACKAGE— auto auto, playwright, playwright-core Which Playwright client package to resolve when browser mode is enabledPORT— 3000 1-65535 Server portPROGRAMFILESPROGRAMFILES(X86)PROXY_URL— USE_PROXY=true =http://127.0.0.1:7890 open-websearch serveSEARCH_MODE— auto request, auto, playwright Search strategy. Currently only affects Bing: request only, request then Playwright fallback, or force PlaywrightUSE_PROXY— true PROXY_URL=http://127.0.0.1:7890 open-websearch serve[](https://m8ven.ai/mcp/aas-ee-open-websearch-bwx3z4)