mcp-node runs commands for whoever holds the token. Treat the token like a root password.
Please don't open a public issue. Report privately:
- GitHub: Security tab → Report a vulnerability
- Email:
l46983284@gmail.com, subjectmcp-node security
Include the version or commit, steps to reproduce, and the impact.
You'll get a reply within a few days. Fixes ship as a new patch release.
Only the latest release gets security fixes.
In scope:
- Reaching any tool without a valid token
- Bypassing the
HostorOriginallowlist - Request smuggling or desync in the HTTP layer
- Exceeding the configured resource caps (output, connections, sessions, request size)
- One session reading or killing another without its id
- Connecting to a hub as a node without that node's secret
- Audit log records altered, removed or reordered without
audit-verifynoticing
Out of scope:
- A token holder running commands or reading and writing any file. That's the product.
- DoS by an authenticated caller within configured limits
- Token theft from your own infrastructure
- Deployments with
MCP_NODE_INSECURE=1
-
Keep the default
127.0.0.1bind. For remote machines, use reverse connect withMCP_NODE_CONNECT_TLS=1; to expose the HTTP API directly, put a TLS proxy or a VPN in front of it. -
Keep the token file at
0600and rotate it if exposed. -
Leave
MCP_NODE_ALLOWED_HOSTSandMCP_NODE_ALLOWED_ORIGINSat their defaults unless you need more. -
Run as a dedicated, unprivileged user. Root isn't needed.
-
Verify what you install.
SHA256SUMS.txtis signed keyless by the release workflow (Sigstore bundleSHA256SUMS.txt.sigstore.json), and every archive carries a GitHub build provenance attestation. With cosign installed,MCP_NODE_VERIFY=requiremakesinstall.shrefuse anything unsigned. By hand:cosign verify-blob SHA256SUMS.txt --bundle SHA256SUMS.txt.sigstore.json \ --certificate-identity "https://github.com/alexchen-sys/mcp-node-zig/.github/workflows/release.yml@refs/tags/v<version>" \ --certificate-oidc-issuer https://token.actions.githubusercontent.com gh attestation verify mcp-node-v<version>-<target>.tar.gz --repo alexchen-sys/mcp-node-zig
-
Turn on the audit log (
MCP_NODE_AUDIT_FILE) and keep its key off the audited machine where you can.