MCP server providing comprehensive Korean legal data access (laws, precedents, regulations, ordinances) with citation verification, temporal comparison, impact graphs, and legal research workflows.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
xmldom: Uncontrolled recursion in XML serialization leads to DoS
xmldom has XML injection through unvalidated DocumentType serialization
xmldom has XML node injection through unvalidated comment serialization
xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion
xmldom has XML node injection through unvalidated processing instruction serialization
process.env. You'll be asked to provide them before it can run.ACCESS_LOGCORS_ORIGINFALLBACK_RATE_LIMIT_RPMKOREAN_LAW_API_KEYLAW_API_PROTOCOL— 폐쇄망/인증서 문제 환경을 위해 =http 옵션 추가(기본 https). 판례 재검색 키워드 후보 생성 개선으로 매칭률 향상. (외부 PR #41/#42)LAW_EXTERNAL_HTTPS_PROXY— setx http://proxy-host:8080 /MLAW_EXTERNAL_TLS_REJECT_UNAUTHORIZED— setx 0 /MLAW_OC— "": "honggildong"LAW_REFERERLAW_RESPONSE_TYPELAW_USER_AGENT— fetch-with-retry.ts에 일반 브라우저 UA 기본 헤더 주입 — 호출자 코드 변경 0, 한 줄 패치로 모든 도구 복구. 환경변수로 override 가능MCP_BODY_LIMITMCP_MAX_BATCH_CALLS— v4.7.0 보안·운영 패치 동봉: JSON-RPC 배치의 tools/call을 개수만큼 rate limit·폴백 쿼터에 계수(배치 증폭 차단, 요청당 상한 20 — ) + graceful shutdown idle 연결 정리(clean exit) + get_article_history lawName 정확매칭 우선(가나다순 오매칭 방지)NO_COLORRATE_LIMIT_RPMTRUST_PROXY— 보안 High 2건 — fetch-with-retry.ts 타임아웃/네트워크 에러에 API 키 포함 URL이 로그로 유출되던 문제 → maskSensitiveUrl()로 OC= 마스킹. trust proxy true → 환경변수(기본 1), X-Forwarded-For 스푸핑 rate limit 우회 차단[](https://m8ven.ai/mcp/pragato-throwaway-korean-law-mcp-unclean-184ui3)