Production-grade MCP server for RetailCRM e-commerce CRM. Provides 39 tools and 2 prompt skills to manage orders, customers, products, inventory, payments, tasks, references, and analytics via API v5.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
process.env. You'll be asked to provide them before it can run.HOST— PORT / No HTTP server bind (default 3000 / 127.0.0.1, --http mode only)PORT— / HOST No HTTP server bind (default 3000 / 127.0.0.1, --http mode only)RETAILCRM_API_KEY— Yes API key (sent via the X-API-KEY header)RETAILCRM_DNS_PROTECTION— No off to disable DNS-rebinding protection (HTTP mode)RETAILCRM_DOMAIN— Yes Your RetailCRM domain (e.g. yourstore.retailcrm.ru)RETAILCRM_HTTP_ALLOWED_HOSTS— No Comma-separated allowed Host values for DNS-rebinding protectionRETAILCRM_RATE_LIMIT— No Client-side requests/second cap (RetailCRM allows ~10/s)RETAILCRM_READONLY— No 1 to expose only read tools (hide create/update/merge/delete)RETAILCRM_URL— is still accepted as a fallback for RETAILCRM_DOMAIN.[](https://m8ven.ai/mcp/theyahia-retailcrm-mcp-1ee4z6)