The vulnerable s lab MCP server provides intentionally vulnerable web services for pentesting practice. It exposes common vulnerabilities like SQL injection, XSS, and CSRF for hands-on learning. The server connects to a collection of vulnerable web applications and APIs. Developers and security professionals use it to test and improve their penetration testing skills in a controlled environment.
The vulnerable s lab MCP server provides intentionally vulnerable web services for pentesting practice. It exposes common vulnerabilities like SQL injection, XSS, and CSRF for hands-on learning. The server connects to a collection of vulnerable web applications and APIs. Developers and security professionals use it to test and improve their penetration testing skills in a controlled environment.
Add this configuration to your claude_desktop_config.json:
{
"mcpServers": {
"appsecco-vulnerable-mcp-servers-lab-github": {
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/server-appsecco-vulnerable-mcp-servers-lab-github"
]
}
}
}Restart Claude Desktop, then ask:
"What tools do you have available from vulnerable s lab?"
No configuration required. This server works out of the box.
"What resources are available in vulnerable s lab?"
Claude will query available resources and return a list of what you can access.
"Show me details about [specific item] in vulnerable s lab"
Claude will fetch and display detailed information about the requested item.
"Create a new [item] in vulnerable s lab with [details]"
Claude will use the appropriate tool to create the resource and confirm success.
We build custom MCP integrations for B2B companies. From simple connections to complex multi-tool setups.