Open-source MCP server that interfaces with FortiMail Engine API for email security management, enabling queue triage, log investigation, reporting, and more.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
process.env. You'll be asked to provide them before it can run.FORTIMAIL_CACHE_BACKEND— No memory memory or redisFORTIMAIL_ENGINE_API_KEY— stdio MCP runs on the operator machine. is process env — not passed to the model in normal tool flows.FORTIMAIL_ENGINE_URL— Yes — Engine base URL including /v1FORTIMAIL_VERIFY_CERT— TLS — verify by default; set =false only when appropriateMCP_HTTP_API_KEY— HTTP Protect POST /mcp with MCP_HTTP_BEARER_TOKEN and/or when not on localhost.MCP_HTTP_BEARER_TOKEN— HTTP Protect POST /mcp with and/or MCP_HTTP_API_KEY when not on localhost.MCP_HTTP_DEBUG_AUTHMCP_HTTP_HOST— No 0.0.0.0 Bind address for HTTPMCP_ICON_URLMCP_SERVER_TITLEMCP_WEBSITE_URLPORT— TRANSPORT=http =3000 MCP_HTTP_BEARER_TOKEN=secret pnpm startREDIS_URL— No redis://127.0.0.1:6379 Redis URLTRANSPORT— http PORT=3000 MCP_HTTP_BEARER_TOKEN=secret pnpm start[](https://m8ven.ai/mcp/lynsoft-fortimail-mcp-server-174x6d)