SSH Session MCP fills a gap in the MCP ecosystem by offering a persistent shared SSH PTY runtime, not just stateless command execution. It features browser collaboration, input locking, safe/full execution modes, async command tracking, configurable policy rules, and multi-device profiles. Ideal for remote development, embedded systems, infrastructure workflows, and hardware control scenarios.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
When Vitest UI server is listening, arbitrary file can be read and executed
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
ws: Uninitialized memory disclosure
process.env. You'll be asked to provide them before it can run.AUTO_OPEN_TERMINAL— defaults to false in the container because browser auto-open from inside a container is usually not useful.DEVICE_A_PASSWORD— "auth": { "passwordEnv": "" },SSH_HOST— YOUR_DEVICE_HOSTSSH_KEY— Local private key path emptySSH_KEY_FILE— File containing the SSH private key emptySSH_MCP_AUTH_MODE— off or proxy offSSH_MCP_AUTH_ROLE_HEADER— Authenticated role header name x-ssh-session-mcp-roleSSH_MCP_AUTH_USER_HEADER— Authenticated user header name x-ssh-session-mcp-userSSH_MCP_CONFIG— e =/workspace/ssh-session-mcp.config.json \SSH_MCP_DEBUG— Enable debug browser actions falseSSH_MCP_DISABLE_MAINSSH_MCP_INSTANCE— Runtime isolation key proc-<pid> or helper-selectedSSH_MCP_LOCAL— Launch a local shell instead of SSH falseSSH_MCP_LOG_DIR— Metadata log directory platform defaultSSH_MCP_LOG_MODE— off, meta, or stderr logging offSSH_MCP_MODE— safe or full safeSSH_MCP_NODE_ID— Stable logical node id for this replica runtime instance idSSH_MCP_PUBLIC_BASE_URL— Public viewer base URL advertised to other replicas unsetSSH_MCP_REDIS_URL— Redis connection URL required when SSH_MCP_STORE=redisSSH_MCP_RUNTIME_MODE— single-node or distributed single-nodeSSH_MCP_STATE_DIR— Runtime state root directory platform defaultSSH_MCP_STORE— Distributed v0 requires Redis for real multi-node deployments. =memory only exists for local skeleton testing and does not provide a shared store across replicas.SSH_MCP_TRUST_PROXY— Whether to trust authenticated proxy headers falseSSH_MCP_USE_MARKERSSH_PASSWORD— Password auth emptySSH_PASSWORD_FILE— File containing the SSH password emptySSH_PORT— Legacy single-target SSH port 22SSH_USER— YOUR_DEVICE_USERVIEWER_HOST— e =0.0.0.0 \VIEWER_LAUNCH_MODEVIEWER_PORT— The image defaults to 8793 when unset so the browser viewer can be published reliably.XDG_CONFIG_HOMEXDG_STATE_HOME[](https://m8ven.ai/mcp/zw-awa-ssh-session-mcp-1huf67)