MCP server exposing all 504 GCHQ CyberChef operations as AI tools
6.6K
⚠️ Security advisory — upgrade to
2.4.1or1.9.1GHSA-rmg9-8936-vx66 (CVSS 5.9)
Every tag below
2.4.1on the v2 line, and below1.9.1on the v1 line, is affected — that is1.4.0through2.4.0, including allrelease-v*tags.The operation cache keyed entries on only the first 1,000 characters of the input, so two different inputs sharing that prefix collided. The second caller received the first caller's result — a silently wrong answer, and on a shared server, one caller receiving output computed from another caller's data.
Patched 2.4.1(current) ·1.9.1(Apache-2.0 maintenance line)Mitigation without upgrading CYBERCHEF_CACHE_ENABLED=falselatestalready points at 2.4.1Older tags are kept deliberately so pinned deployments and reproducible builds do not break. They are not maintained and will not receive fixes. Pin to
2.4.1or later.
A Model Context Protocol (MCP) server wrapping GCHQ CyberChef, the "Cyber Swiss Army Knife". It exposes 504 data-manipulation operations — encryption, encoding, compression, hashing, forensics — as tools an AI assistant can call directly.
Source & docs: https://github.com/doublegate/CyberChef-MCP · Licence: GPL-3.0-or-later (v1.9.x and earlier are Apache-2.0)
docker pull parobek/cyberchef-mcp:latest
echo '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}' \
| docker run -i --rm parobek/cyberchef-mcp:latest
The -i flag is required. Without stdin the container exits immediately — the single most
common setup mistake.
{
"mcpServers": {
"cyberchef": {
"command": "docker",
"args": ["run", "-i", "--rm", "parobek/cyberchef-mcp:latest"]
}
}
}
Works with Claude Desktop, Claude Code, Cursor, and any client that speaks MCP over stdio.
tools/list returns about 24 tools, not 504 — deliberately. Sending 504 tool schemas on every
request costs roughly 86,000 tokens before the user types anything, so the default surface is an
index:
| Tool | Purpose |
|---|---|
cyberchef_bake | Run a recipe. Reaches any of the 504 operations by name. |
cyberchef_search | Find an operation by keyword. |
cyberchef_categories | Browse the 16 operation categories. |
cyberchef_list_operations | List the operations in one category. |
cyberchef_describe_operation | Full argument schema for the operations you chose. |
cyberchef_magic | Detect what an unknown blob is. Present in every surface. |
Plus recipe management, batching, and cache/quota tools.
Nothing is unreachable. Every one of the 504 operations is reachable through this index — verified, not asserted: walking every category reaches 504/504 and describes 504/504.
Prefer the old behaviour? One variable:
# All 524 tools, ~86,000 tokens per tools/list
docker run -i --rm -e CYBERCHEF_TOOL_SURFACE=all parobek/cyberchef-mcp:latest
# A middle ground: ~100 tools, ~16,600 tokens
docker run -i --rm -e CYBERCHEF_TOOL_SURFACE=curated parobek/cyberchef-mcp:latest
| Tag | Meaning |
|---|---|
latest | Newest release from the default branch |
2.1.0, 2.1, 2 | Specific version, minor line, major line |
1.9.0, 1.9, 1 | The frozen v1 line — Apache-2.0, security patches only until ~March 2027 |
release-v1.x.x tags predate the current scheme and are kept so older references keep working.
Also on GHCR: ghcr.io/doublegate/cyberchef-mcp_v4 (major-versioned).
# Decode, decompress and extract indicators in one call
echo '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{
"name":"cyberchef_bake","arguments":{
"input":"H4sIAAAAAAAA/...",
"recipe":[{"op":"From Base64"},{"op":"Gunzip"},{"op":"Extract IP addresses"}]}}}' \
| docker run -i --rm parobek/cyberchef-mcp:latest
Eight runnable examples — quickstart, recipes, discovery, forensic triage, saved recipes, batching,
multi-client HTTP, shell usage — are in
examples/, and CI executes them
on every change.
Common variables (the User Guide documents all of them):
| Variable | Default | Meaning |
|---|---|---|
CYBERCHEF_TOOL_SURFACE | index | index, curated or all |
CYBERCHEF_TRANSPORT | stdio | stdio, http, or socket (Unix domain socket / loopback TCP) |
CYBERCHEF_MAX_INPUT_SIZE | 104857600 | Maximum input, in bytes |
CYBERCHEF_OPERATION_TIMEOUT | 30000 | Per-operation timeout, in ms |
LOG_LEVEL | info | Diagnostics verbosity (written to stderr) |
docker run --rm -p 3000:3000 \
-e CYBERCHEF_TRANSPORT=http \
-e CYBERCHEF_HTTP_HOST=0.0.0.0 \
-e CYBERCHEF_ALLOWED_HOSTS=localhost:3000,127.0.0.1:3000 \
parobek/cyberchef-mcp:latest
Serves many clients, each with its own session. DNS-rebinding protection is on by default, so a
non-loopback bind needs CYBERCHEF_ALLOWED_HOSTS.
nonroot); both base images digest-pinneddocker run -i --rm --read-only --tmpfs /tmp:size=100M \
--cap-drop=ALL --security-opt=no-new-privileges parobek/cyberchef-mcp:latest
Content type
Image
Digest
sha256:cbe2f64f1…
Size
144.6 MB
Last updated
18 days ago
docker pull parobek/cyberchef-mcp