The vulnerable s lab MCP server provides intentionally vulnerable web services for pentesting practice. It exposes common vulnerabilities like SQL injection, XSS, and CSRF for hands-on learning. The server connects to a collection of vulnerable web applications and APIs. Developers and security professionals use it to test and improve their penetration testing skills in a controlled environment.
The vulnerable s lab MCP server provides intentionally vulnerable web services for pentesting practice. It exposes common vulnerabilities like SQL injection, XSS, and CSRF for hands-on learning. The server connects to a collection of vulnerable web applications and APIs. Developers and security professionals use it to test and improve their penetration testing skills in a controlled environment.
Add this configuration to your claude_desktop_config.json:
{
"mcpServers": {
"appsecco-vulnerable-mcp-servers-lab-github": {
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/server-appsecco-vulnerable-mcp-servers-lab-github"
]
}
}
}Restart Claude Desktop, then ask:
"What tools do you have available from vulnerable s lab?"
No configuration required. This server works out of the box.
"What resources are available in vulnerable s lab?"
Claude will query available resources and return a list of what you can access.
"Show me details about [specific item] in vulnerable s lab"
Claude will fetch and display detailed information about the requested item.
"Create a new [item] in vulnerable s lab with [details]"
Claude will use the appropriate tool to create the resource and confirm success.
See what tools in your stack can connect to AI.
We build custom MCP integrations for B2B companies. From simple connections to complex multi-tool setups.