Skip to content

Security

WaveXisMCP takes security seriously. This page covers the built-in protections and how to configure them.

SSRF protection

All URL-based tools validate against SSRF (Server-Side Request Forgery) attacks:

  • Private IP ranges (127.0.0.0/8, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) are blocked by default
  • localhost and 0.0.0.0 are rejected
  • IPv6 loopback (::1) and link-local (fe80::/10) are blocked
  • Metadata endpoints (169.254.169.254) are blocked
  • Alternate IP spellings (hex, octal, shorthand like 127.1) are normalized and blocked
  • Hostname-based DNS rebinding is an inherent TOCTOU limitation: the check happens before DNS resolution by the browser

Allow private IPs

If you need to access internal services, set the environment variable:

export WAVEXIS_MCP_ALLOW_INTERNAL_URLS=1

Security risk

Enabling private IP access allows the LLM to reach internal services. Only do this in trusted environments.

Path sandboxing

All file-writing tools (screenshots, PDFs, HAR files, videos) write to a sandboxed output directory:

  • Default: current working directory
  • Override with WAVEXIS_MCP_OUTPUT_DIR=/path/to/output
  • Paths that escape the sandbox via .. are rejected
  • Absolute paths outside the sandbox are rejected
# Set a dedicated output directory
export WAVEXIS_MCP_OUTPUT_DIR=/tmp/wavexis-output

Rate limiting

WaveXisMCP includes built-in rate limiting to prevent runaway tool calls:

  • Default: 60 calls/second per session, burst of 10
  • Configurable via CLI flags: --rate-limit 120 --rate-burst 20
  • Set --rate-limit 0 to disable
  • Stateless calls (no session_id) share a global bucket

See Rate Limiting for details.

Raw protocol access

The workflows tier provides raw CDP/BiDi access via an allowlist:

  • By default only read-only commands are allowed (*.get*, Page.capture*, Page.printToPDF, and session.status)
  • Override with WAVEXIS_MCP_ALLOW_RAW_COMMANDS=all to permit arbitrary commands

Danger

Raw protocol access bypasses all abstractions. Only enable experimental when you understand the risks.

Stealth mode

Stealth mode hides browser automation fingerprints:

  • Removes navigator.webdriver
  • Falsifies plugins and languages
  • Mimics real Chrome runtime properties
  • Does not bypass CAPTCHAs or Cloudflare challenges by itself

Enable with:

uvx wavexis-mcp --caps all

Then use stealth=true in wavexis_session_open.

Browser process isolation

Each session launches a separate browser process:

  • No shared state between sessions
  • Sessions are cleaned up on disconnect
  • Browser processes are killed on session close
  • No persistent cookies or history between sessions (unless user_data_dir is set)

Reporting vulnerabilities

See SECURITY.md for the supported version table and vulnerability reporting process.