VYPR

npm package

hackmd-mcp

pkg:npm/hackmd-mcp

Vulnerabilities (1)

  • CVE-2025-59155MedSep 15, 2025
    affected >= 1.4.0, < 1.5.0fixed 1.5.0

    hackmd-mcp is a Model Context Protocol server for integrating HackMD's note-taking platform with AI assistants. From 1.4.0 to before 1.5.0, hackmd-mcp contains a server-side request forgery (SSRF) vulnerability when the server is run in HTTP transport mode. Arbitrary hackmdApiUrl