An MCP server for web search, web fetching, and Context7 documentation tools with proxy support, designed for internal network environments.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
When Vitest UI server is listening, arbitrary file can be read and executed
Vitest allows Remote Code Execution when accessing a malicious website while Vitest API server is listening
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
undici WebSocket client vulnerable to denial of service via fragment count bypass
undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse
process.env. You'll be asked to provide them before it can run.BOCHA_API_KEY— 博查 AI 的 Bearer TokenCONTEXT7_API_KEY— Context7 可选鉴权: 支持 ,不配置也可匿名基础使用CONTEXT7_MCP_URL— Context7 MCP URL,默认 https://mcp.context7.com/mcpENABLE_CONTEXT7— 是否启用 Context7;默认启用,设置为 false 可关闭HTTPS_PROXY— / HTTP_PROXY 代理地址HTTP_PROXY— HTTPS_PROXY / 代理地址IGNORE_SSL— 忽略 SSL 证书校验 (设置为 true)PROXYTIMEOUTWEB_SEARCHhttp_proxyhttps_proxy[](https://m8ven.ai/mcp/chenpu17-web-bridge-mcp-12scay)