Deprecated - Model Context Protocol (MCP) Server for the JFrog Platform API, enabling repository management, build tracking, release lifecycle management, and more.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
process.env. You'll be asked to provide them before it can run.CORS_ORIGIN— CORS origin allowed for SSE connections (default: '')JFROG_ACCESS_TOKEN— Your JFrog access token (required)JFROG_URL— Base URL for your JFrog platform (required)LOG_LEVEL— Logging level: DEBUG, INFO, WARN, ERROR (default: INFO)MAX_RECONNECT_ATTEMPTS— Maximum number of reconnection attempts for SSE server (default: 5)PORT— Port number to use for SSE transport (default: 8080)RECONNECT_DELAY_MS— Base delay in milliseconds between reconnection attempts (default: 2000)TRANSPORT— Transport mode to use, set to 'sse' to enable SSE transport (default: stdio)[](https://m8ven.ai/mcp/jfrog-mcp-jfrog-1t3qki)