Provides tools to manage SSH targets and generate one-time WebShell terminal sessions through an integrated gateway. It enables AI agents to facilitate remote server access by creating and managing secure, browser-based terminal links.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
ws affected by a DoS when handling a request with many HTTP headers
express vulnerable to XSS via response.redirect()
process.env. You'll be asked to provide them before it can run.MOCK_WEBSHELL_PORT— :内联 WebShell Gateway HTTP/WS 端口,默认 9100PORT— :MCP HTTP 服务端口,默认 3001SSH_WEBSHELL_API_TOKEN— :调用 WebShell 网关受保护接口时使用的固定 API Token(内联 Gateway 当前不会强制校验,仅用于兼容旧配置)SSH_WEBSHELL_API_URL— 容器内部 MCP 通过 =http://localhost:9100 调用内联 GatewaySSH_WEBSHELL_HTTP_TIMEOUT_MS— :请求超时,默认 15000WEBSHELL_DB_DATABASE— e =webshell \WEBSHELL_DB_HOST— e =<你的 MySQL 主机地址> \WEBSHELL_DB_PASSWORD— e =webshell_pass \WEBSHELL_DB_PORT— :数据库端口,默认 3306WEBSHELL_DB_USER— e =webshell \WEBSHELL_PUBLIC_BASE_URL— :会话链接对外暴露的基础地址,默认 http://localhost:9100[](https://m8ven.ai/mcp/have-myn-ssh-mcp-9uq41c)