We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/michoo/security_mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server
dynamic-code-injection.py•294 B
# The following code is vulnerable to arbitrary code execution because it runs dynamic Python code based on untrusted data.
from flask import request
@app.route("/")
def example():
operation = request.args.get("operation")
eval(f"product_{operation}()") # Noncompliant
return "OK"