52
/ 100
16 days ago
glama

MongoDB MCP Server

Enables an IDE agent to read and write MongoDB through typed, allowlisted tools, with safety defaults and support for CRUD, aggregation, and collection listing.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
⚠️
Known vulnerabilities in dependencies: 4 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
6 tools verified — handlers match their declared behaviour
3 read-only tools verified — handlers contain no write/delete/exec
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
// known CVEs in dependencies4 high

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.17.1GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

high@modelcontextprotocol/sdk@1.17.1GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.17.1GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

highmongoose@8.17.0GHSA-wpg9-53fq-2r8h

Mongoose's Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configMCP_ALLOWED_COLLECTIONSFail closed on collections: require or explicit MCP_ALLOW_ALL_COLLECTIONS=true
configMCP_ALLOW_ALL_COLLECTIONSFail closed on collections: require MCP_ALLOWED_COLLECTIONS or explicit =true
configMCP_ALLOW_HARD_DELETEHard delete disabled unless =true
configMCP_DEFAULT_LIMIT10 Default read limit
configMCP_MAX_LIMITCaps limit at (default 100)
configMCP_MAX_OBJECT_DEPTH32 Max nested object depth in queries
configMCP_MAX_REGEX_LENGTH200 Max $regex pattern length
configMCP_READ_ONLYOptional =true disables all mutating tools
configMONGODB_URI"": "mongodb://localhost:27018/mcp-server",
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 6 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/tatisstiv-mcp-server-11br93)](https://m8ven.ai/mcp/tatisstiv-mcp-server-11br93)
commit: 950bbda35361f2fc5c40e47a67a3682b65939df2
code hash: 92cf192d5a590dc6a6c65ecb792ac2466d0504fe8b6b9aff442be7263f2da8b4
verified: 7/15/2026, 8:43:40 AM
view raw JSON →