Enables LLMs to make HTTP requests with OAuth2, session cookies, retry logic, and cURL command generation, while providing security features like SSRF protection and TLS enforcement.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client
Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation
process.env. You'll be asked to provide them before it can run.HTTP_ALLOW_INSECURE_OAUTH— (未設定) 1 で OAuth2 token_url / device_authorization_url の http:// 接続を許可(デフォルトは HTTPS のみ。クライアントシークレット流出を防ぐためテスト用途以外では未設定推奨)HTTP_ALLOW_INSECURE_TLS— (未設定) 1 で reject_unauthorized: false を尊重。未設定の場合は警告して TLS 検証を強制HTTP_ALLOW_PRIVATE— (未設定) 1 で SSRF ガード無効化(loopback / 10/8 / 172.16/12 / 192.168/16 / 169.254/16 / IPv6 ULA / localhost / .internal 等を許可)HTTP_DOWNLOAD_ROOT— (未設定) download の出力先許可ディレクトリ。未設定だと download は失敗。output_path はこの配下のみ許可、UNC パス (\\?\, \\server\) は拒否HTTP_USER_AGENT— http-mcp/<package version> 既定の User-Agent (package.json の version を反映)[](https://m8ven.ai/mcp/cudgk-http-mcp-17jabu)