Damn Vulnerable MCP Server
Damn Vulnerable Model Context Protocol (DVMCP)
A deliberately vulnerable MCP server, a training lab of 10 challenges on attacks against MCP, run only in isolation
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- A deliberately vulnerable server with no safeguards, dangerous outside isolation
- Challenges include arbitrary code execution and remote system access
Install
Manual install
docker build -t dvmcp .
docker run -p 9001-9010:9001-9010 dvmcpRecommended way, run only in isolation. Ports 9001 through 9010 map to the challenges.
This is third-party code. Review the repository files before installing.
What it does
This is a training lab with intentional vulnerabilities, in the spirit of projects like DVWA. It bundles 10 challenges of rising difficulty, each showing a class of attack on MCP: prompt injection, tool description poisoning, excessive permissions, tool definition mutation, tool shadowing, indirect injection through data, token theft, arbitrary code execution, remote access and a combined attack. Each challenge is a separate MCP server on its own port that a client connects to. The repository ships solution and mitigation write-ups. The lab targets security researchers, MCP developers and AI safety specialists learning to find and close such gaps.
Who it is for. For security researchers, MCP developers and AI safety specialists studying MCP vulnerabilities hands-on.
Good fit when
- You want to study MCP attack classes hands-on in an isolated environment
- You want to test detection and defenses against knowingly vulnerable servers
- You need training material for a team or a CTF on MCP security
Not a fit when
- You have no isolated environment: a work or shared machine with real data is unsuitable
- You need a safe production MCP server, not a training target
Example request
Explain how the tool poisoning challenge hides a malicious instruction and propose a defenseLimitations
This is a knowingly insecure lab, not a production-ready server. Run it only in isolation, for example in Docker or a dedicated virtual machine, with no real data, tokens or exposure to an external network. The author notes it is unstable on Windows and recommends Docker or Linux. It needs Python 3.10 or newer, and node for the remote servers.
How to disable. Stop and remove the Docker container or the server processes, and delete the cloned repository from disk.
MCP
- Transport
- sse, stdio
- Authentication
- not required
Security check
- A deliberately vulnerable server with no safeguards, dangerous outside isolation
- Challenges include arbitrary code execution and remote system access
README in short
The README presents a deliberately vulnerable MCP implementation for learning and lists 10 challenges across easy, medium and hard levels. Each challenge shows a vulnerability type, from prompt injection to code execution and remote access, and runs as a separate server on ports 9001 through 9010. The quick start offers a Docker build and run, and there is a from-source install with pip. The author warns about instability on Windows and recommends Docker or Linux. The repository includes setup docs, an MCP overview and solution write-ups.
FAQ
Is it safe to run?
The lab is deliberately vulnerable. Run it only in isolation, with no real data or external network exposure, otherwise the code execution and remote access challenges are dangerous.
Are there solution write-ups?
Yes, the solutions folder has a write-up for each challenge, including how to defend against it.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents