Enables AI agents to create and manipulate live visual diagrams on an Excalidraw canvas in real-time via MCP tools.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
express-rate-limit: IPv4-mapped IPv6 addresses bypass per-client rate limiting on servers with dual-stack network
ws affected by a DoS when handling a request with many HTTP headers
ws: Memory exhaustion DoS from tiny fragments and data chunks
vite: `server.fs.deny` bypass on Windows alternate paths
Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket
process.env. You'll be asked to provide them before it can run.HOST— localhost Canvas server hostLOG_LEVELPORT— 3031 Canvas server portAUTH_ENABLEDJWT_SECRETALLOWED_ORIGINSCANVAS_AUTO_START— true Auto-start canvas server with MCP serverSYNC_RETRY_ATTEMPTS— 3 Number of retry attempts for failed operationsSYNC_RETRY_DELAY_SECONDS— 1.0 Base delay between retry attempts (seconds)SYNC_RETRY_MAX_DELAY_SECONDS— 30.0 Maximum delay between retry attempts (seconds)SYNC_RETRY_EXPONENTIAL_BASE— 2.0 Exponential base for backoff calculationSYNC_RETRY_JITTER— true Enable/disable jitter for retry delaysMAX_ELEMENTSSTRUCTURED_LOGGINGJSON_LOGGINGLOG_FILEAUDIT_LOG_FILEMONITORING_ENABLEDMETRICS_ENABLEDALERTING_ENABLEDHEALTH_CHECK_INTERVALCPU_THRESHOLDMEMORY_THRESHOLDWEBSOCKET_ENABLEDWEBSOCKET_HOSTWEBSOCKET_PORTWEBSOCKET_AUTH_ENABLEDWEBSOCKET_TLS_ENABLEDWEBSOCKET_CERT_FILEWEBSOCKET_KEY_FILEWEBSOCKET_CA_FILEWEBSOCKET_METRICS_ENABLEDWEBSOCKET_METRICS_PORTENVIRONMENTEXCALIDRAW_JWT_SECRETEXCALIDRAW_TOKEN_EXPIRYEXCALIDRAW_AUTH_ENABLED[](https://m8ven.ai/mcp/lesleslie-excalidraw-mcp-1dthwa)