MCP server enabling AI assistants to interact with ClickUp workspaces, including task management, comments, time tracking, and document operations.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client
Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation
Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression
undici WebSocket client vulnerable to denial of service via fragment count bypass
Undici has an HTTP Request/Response Smuggling issue
process.env. You'll be asked to provide them before it can run.CLICKUP_API_KEY— Your (Profile Icon > Settings > Apps > API Token ~ usually starts with pk_)CLICKUP_MCP_MODE— env =read-minimal \CLICKUP_PRIMARY_LANGUAGE— LANG: (Optional) If is not set, the MCP will check this standard environment variable (e.g., "en_US.UTF-8", "de_DE") as a fallback to infer the primary language.CLICKUP_TEAM_ID— Your (The 7–10 digit number in the URL when you are in the settings)MAX_IMAGES— (Optional) The maximum number of images to return for a task in getTaskById. Defaults to 4.MAX_RESPONSE_SIZE_MB— (Optional) The maximum response size in megabytes for getTaskById. Uses intelligent size budgeting to fit the most important images within the limit. Defaults to 1.[](https://m8ven.ai/mcp/sebastienheyd-clickup-mcp-109v8h)