MCP Trust Registry › damn-vulnerable-mcp-server

Is damn-vulnerable-mcp-server MCP server safe?

Vulnerable
Is damn-vulnerable-mcp-server safe to connect? As of 2026-07-20, Pinaka Radar's continuous scan rates it Vulnerable: it carries an exploitable finding, with 45 findings across its 49 tools.
Verdict VulnerableLanguage pythonTools 49Source https://github.com/harishsg993010/damn-vulnerable-MCP-serverLast scanned 2026-07-20

Findings (45)

SeverityFindingToolDetail
HIGHdescription poisoning AS-GI-002get_user_profileHidden/injection markers in MCP tool description
HIGHcode execution AS-TS-001run_system_diagnosticMCP tool can execute shell/eval
HIGHcode execution AS-TS-001execute_python_codeMCP tool can execute shell/eval
HIGHcode execution AS-TS-001execute_shell_commandMCP tool can execute shell/eval
HIGHcommand injection AS-TS-004evaluate_expressionTool parameter reaches a shell/eval sink (command injection)
HIGHcommand injection AS-TS-004ping_hostTool parameter reaches a shell/eval sink (command injection)
HIGHcommand injection AS-TS-004tracerouteTool parameter reaches a shell/eval sink (command injection)
HIGHcommand injection AS-TS-004port_scanTool parameter reaches a shell/eval sink (command injection)
HIGHcommand injection AS-TS-004network_diagnosticTool parameter reaches a shell/eval sink (command injection)
HIGHdescription poisoning AS-GI-002remote_accessHidden/injection markers in MCP tool description
HIGHdescription poisoning AS-GI-002get_company_dataHidden/injection markers in MCP tool description
HIGHdescription poisoning AS-GI-002search_company_databaseHidden/injection markers in MCP tool description
HIGHcommand injection AS-TS-004execute_commandTool parameter reaches a shell/eval sink (command injection)
HIGHpath traversal AS-TS-006upload_and_process_documentTool parameter reaches a filesystem path (path traversal)
HIGHdescription poisoning AS-GI-002calculateHidden/injection markers in MCP tool description
HIGHcommand injection AS-TS-004calculateTool parameter reaches a shell/eval sink (command injection)
HIGHdescription poisoning AS-GI-002enhanced_calculateHidden/injection markers in MCP tool description
HIGHcommand injection AS-TS-004enhanced_calculateTool parameter reaches a shell/eval sink (command injection)
HIGHhardcoded secret AS-SE-001(server)Hardcoded secret in MCP tool/server code
HIGHhardcoded secret AS-SE-001(server)Hardcoded secret in MCP tool/server code
HIGHhardcoded secret AS-SE-001(server)Hardcoded secret in MCP tool/server code
HIGHhardcoded secret AS-SE-001(server)Hardcoded secret in MCP tool/server code
MEDIUMimperative wording AS-GI-001get_user_profileImperative language in MCP tool description
MEDIUMimperative wording AS-GI-001malicious_check_system_statusImperative language in MCP tool description
MEDIUMpath traversal AS-TS-006get_configTool parameter reaches a filesystem path (path traversal)
MEDIUMimperative wording AS-GI-001get_company_dataImperative language in MCP tool description
MEDIUMimperative wording AS-GI-001search_company_databaseImperative language in MCP tool description
MEDIUMpath traversal AS-TS-006read_fileTool parameter reaches a filesystem path (path traversal)
MEDIUMpath traversal AS-TS-006read_fileTool parameter reaches a filesystem path (path traversal)
MEDIUMpath traversal AS-TS-006file_managerTool parameter reaches a filesystem path (path traversal)
MEDIUMpath traversal AS-TS-006read_documentTool parameter reaches a filesystem path (path traversal)
MEDIUMpath traversal AS-TS-006read_uploadTool parameter reaches a filesystem path (path traversal)
MEDIUMimperative wording AS-GI-001calculateImperative language in MCP tool description
MEDIUMimperative wording AS-GI-001enhanced_calculateImperative language in MCP tool description
MEDIUMno consent gate AS-EA-001send_emailSide-effecting tool without an explicit consent gate
LOWcommand injection AS-TS-002analyze_log_fileMCP tool has direct filesystem access
LOWcommand injection AS-TS-002analyze_log_fileMCP tool has direct filesystem access
LOWcommand injection AS-TS-002ping_hostMCP tool has direct filesystem access
LOWcommand injection AS-TS-002tracerouteMCP tool has direct filesystem access
LOWcommand injection AS-TS-002port_scanMCP tool has direct filesystem access
LOWcommand injection AS-TS-002network_diagnosticMCP tool has direct filesystem access
LOWcommand injection AS-TS-002view_network_logsMCP tool has direct filesystem access
LOWcommand injection AS-TS-002search_filesMCP tool has direct filesystem access
LOWcommand injection AS-TS-002search_documentsMCP tool has direct filesystem access
LOWcommand injection AS-TS-002get_weatherMCP tool has direct filesystem access

No tool-definition drift observed since the previous scan.

Watch damn-vulnerable-mcp-server for tool drift

Get an email if this server's tools change — a new tool, a rewritten description, an added capability. One email per change, one-click unsubscribe.