MCP Markdownify Server - Model Context Protocol Server for Converting Almost Anything to Markdown
MCP Markdownify Server is an MCP server that MCP Markdownify Server - Model Context Protocol Server for Converting Almost Anything to Markdown. Its tool list has not been published yet over stdio, requires no API key, and scores 23/100 on MCPpedia's security, maintenance and efficiency rubric.
Config is the same across clients — only the file and path differ.
{
"mcpServers": {
"mcp-markdownify-server": {
"command": "npx",
"args": [
"-y",
"mcp-markdownify-server"
]
}
}
}Are you the author?
Add this badge to your README to show your security score and help users find safe servers.
MCP Markdownify Server - Model Context Protocol Server for Converting Almost Anything to Markdown
Run this in your terminal to verify the server starts. Then let us know if it worked — your result helps other developers.
npx -y 'mcp-markdownify-server' 2>&1 | head -1 && echo "✓ Server started successfully"
After testing, let us know if it worked:
Five weighted categories — click any category to see the underlying evidence.
mcp-markdownify-server vulnerable to command injection in pptx-to-markdown tool
### Summary A command injection vulnerability exists in the `mcp-markdownify-server` MCP Server. The vulnerability is caused by the unsanitized use of input parameters within a call to `child_process.exec`, enabling an attacker to inject arbitrary system commands. Successful exploitation can lead to remote code execution under the server process's privileges. The server constructs and executes shell commands using unvalidated user input directly within command-line strings. This introduces th
Markdownify MCP Server allows attackers to read arbitrary files
All versions of the package mcp-markdownify-server are vulnerable to Files or Directories Accessible to External Parties via the get-markdown-file tool. An attacker can craft a prompt that, once accessed by the MCP host, will allow it to read arbitrary files from the host running the server.
>= 0source →Markdownify MCP Server allows Server-Side Request Forgery (SSRF) via the Markdownify.get() function
All versions of the package mcp-markdownify-server are vulnerable to Server-Side Request Forgery (SSRF) via the Markdownify.get() function. An attacker can craft a prompt that, once accessed by the MCP host, can invoke the webpage-to-markdown, bing-search-to-markdown, and youtube-to-markdown tools to issue requests and read the responses to attacker-controlled URLs, potentially leaking sensitive information.
>= 0source →This server is missing a description. Tools and install config are also missing. If you've used it, help the community.
Add informationBe the first to review
Have you used this server?
Share your experience — it helps other developers decide.
Sign in to write a review.
Others in writing
MCP server for document format conversion using pandoc.
The markdown workspace your AI can read, search, and suggest edits in — every change signed.
Scrape, crawl, and map websites to Markdown or JSON via local CLI.
Model Context Protocol (MCP) Server to connect your AI with any MediaWiki
MCP Security Weekly
Get CVE alerts and security updates for Mcp Markdownify Server and similar servers.
Start a conversation
Ask a question, share a tip, or report an issue.
Sign in to join the discussion.