A comprehensive MCP server providing 92 tools for managing Proxmox Virtual Environment, including QEMU VMs and LXC containers.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
When Vitest UI server is listening, arbitrary file can be read and executed
Vitest allows Remote Code Execution when accessing a malicious website while Vitest API server is listening
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client
Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation
process.env. You'll be asked to provide them before it can run.PROXMOX_ALLOW_ELEVATED— No Allow elevated operations falsePROXMOX_ALLOW_UNSAFE_COMMANDS— No Allow shell special characters in exec commands falsePROXMOX_HOST— Yes Proxmox server hostname or IP address -PROXMOX_LOG_LEVELPROXMOX_PORT— No Proxmox API port 8006PROXMOX_SSH_ENABLED— No Enable SSH-based LXC exec falsePROXMOX_SSH_HOST— No SSH host (falls back to PROXMOX_HOST) -PROXMOX_SSH_HOST_KEY_FINGERPRINT— No Host key fingerprint for verification -PROXMOX_SSH_KEY_PATH— When SSH enabled Path to SSH private key -PROXMOX_SSH_NODE— When SSH enabled Proxmox node name reachable via SSH -PROXMOX_SSH_PORT— No SSH port 22PROXMOX_SSH_USER— No SSH username rootPROXMOX_SSL_CA_CERTPROXMOX_SSL_MODE— No SSL verification mode strictPROXMOX_TOKEN_NAME— Yes API token name -PROXMOX_TOKEN_VALUE— Yes API token value -PROXMOX_USER— No Username with realm (e.g., root@pam) root@pam[](https://m8ven.ai/mcp/bldg-7-proxmox-mcp-1vfqxd)