MySQL MCP Server - Model Context Protocol server for MySQL databases
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
nest allows a remote attacker to execute arbitrary code via the Content-Type header
@nestjs/core Improperly Neutralizes Special Elements in Output Used by a Downstream Component ('Injection')
process.env. You'll be asked to provide them before it can run.ALLOW_DDL— false Allow CREATE/ALTER/DROP/TRUNCATEALLOW_DELETE— false Allow DELETEALLOW_INSERT— false Allow INSERTALLOW_SELECT— true Allow SELECT queriesALLOW_UPDATE— false Allow UPDATEALLOW_VIEW— true Allow SHOW / DESCRIBEDB_HOST— export =localhostDB_NAME— export =your_databaseDB_PASSWORD— export =your_passwordDB_POOL_ACQUIRE_TIMEOUTDB_POOL_MAX— 10 Max pool connectionsDB_POOL_MIN— 2 Min pool connectionsDB_PORT— export =3306DB_QUERY_TIMEOUTDB_USER— export =rootDRY_RUN— Mode Validate SQL queries without returning actual dataLOG_DIR— ./logs Log directoryLOG_LEVEL— info Log level: debug/info/warn/errorMCP_HOSTMCP_PORTMCP_SERVER_NAME— mysql-mcp-server Server name — used as log file prefixMCP_SERVER_VERSIONMCP_TRANSPORT— stdio Transport: stdio/http-sse/streamable-http[](https://m8ven.ai/mcp/johnson-lee-mysql-mcp-server-1fq389)