MCP server for interacting with Gitea, enabling issue and PR management, repository browsing, file reading, and safe git command execution.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
Axios is vulnerable to DoS attack through lack of data size check
process.env. You'll be asked to provide them before it can run.CF_ID— export =your_cf_client_idCF_SECRET— export =your_cf_client_secretGITEA_API_URL— export =https://git.your-instance.com/api/v1GITEA_TOKEN— export =your_tokenMCP_ALLOWED_PATHS— Allowed Paths: Restricted via environment variable.[](https://m8ven.ai/mcp/boringstudio-org-mcp-gitea-l1b88m)