Vulnerable-by-design MCP server for learning object-level / cross-tenant authorization (BOLA/IDOR) bugs + a hunt checklist
mcp authorization ai-security idor security-lab bola llm-security model-context-protocol mcp-security vulnerable-by-design broken-object-level-authorization
-
Updated
Jun 11, 2026 - JavaScript