A self-hostable, vulnerable-by-design MCP server for learning how object-level authorization bugs (BOLA/IDOR) appear in multi-tenant tools.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
process.env. You'll be asked to provide them before it can run.LAB_MODE— note_get and note_update, but (in =vuln) it never calls[](https://m8ven.ai/mcp/wrg-11-mcp-objauthz-lab-147wcx)