Enables agents to run SQL queries against PostgreSQL databases through MCP with connection pooling, tenant isolation, and read-only guardrails. Supports introspection of schemas, tables, and columns.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Fastify's Content-Type header tab character allows body validation bypass
Fastify vulnerable to invalid content-type parsing, which could lead to validation bypass
fastify: request.protocol and request.host Spoofable via X-Forwarded-Proto/Host from Untrusted Connections
Fastify Vulnerable to DoS via Unbounded Memory Allocation in sendWebStream
process.env. You'll be asked to provide them before it can run.ALLOW_PUBLIC_BIND— true — see [Network binding](#network-binding).HEALTH_CACHE_TTL_MS— /health is unauthenticated but its DB pings are cached (,MCP_HTTP_PORT— default (MCP_HTTP_HOST/). Never expose publicly — trusted infra utility.MCP_TOKEN— Identity is process-level: set =<a configured secret>; the process runs withMCP_TRANSPORT— npm run start:mcp:http — streamable HTTP (=http), binds loopback by[](https://m8ven.ai/mcp/duylongpro99-db-query-mcp-1ms99i)