MCP server for Wiki.js with full GraphQL API coverage, fine-grained permissions, multi-user support, and deployable on Vercel.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
mcp-handler has a tool response leak across concurrent client sessions ('Race Condition')
Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n
Next.js Vulnerable to Denial of Service with Server Components
Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades
process.env. You'll be asked to provide them before it can run.WIKIJS_AUDIT— nein true Audit-Log für write/delete/admin (false = aus; nie Secrets)WIKIJS_MAX_CONCURRENCY— nein 8 Max. parallele Upstream-Requests (Overload-Schutz; queued/sheddet bei Überlast)WIKIJS_MCP_VERBOSE— nein false MCP-Request-Logging (true)WIKIJS_PERMISSION_PRESET— Single-Tenant — eine feste Instanz für alle WIKIJS_URL + WIKIJS_TOKEN (+ optional ) nichts (nur die URL …/mcp)WIKIJS_PROFILES— Mehrbenutzer (empfohlen) — viele Nutzer, je eigener Key/Rechte (+ optional WIKIJS_PERMISSION_PRESET) ihren geheimen HandleWIKIJS_RETRIES— nein 2 Retry nur bei Connection-Fehlern (sicher auch für Mutationen)WIKIJS_ROLES— nein – JSON, das die Rollen-Definitionen zur Laufzeit überschreibt (Form wie config/roles.json)WIKIJS_TIMEOUT_MS— nein 30000 Timeout pro GraphQL-Request (AbortController)WIKIJS_TOKEN— .env: WIKIJS_URL + setzen (siehe .env.example)WIKIJS_URL— .env: + WIKIJS_TOKEN setzen (siehe .env.example)WIKI_URL[](https://m8ven.ai/mcp/janschachtschabel-mcp-for-wiki-js-1owe60)