Read-only access to a self-hosted GeoLens spatial catalog: datasets, features, maps, sandboxed SQL.
MCPpedia last refreshed this data
io.github.geolens-io/geolens is an MCP server that read-only access to a self-hosted GeoLens spatial catalog: datasets, features, maps, sandboxed SQL. Its tool list has not been published yet over stdio and sse, requires no API key, and scores 85/100 on MCPpedia's security, maintenance and efficiency rubric.
Config is the same across clients - only the file and path differ.
{
"mcpServers": {
"io-github-geolens-io-geolens": {
"args": [
"-y",
"@geolens/sdk"
],
"command": "npx"
}
}
}Are you the author?
Add this badge to your README to show your security score and help users find safe servers.
Read-only access to a self-hosted GeoLens spatial catalog: datasets, features, maps, sandboxed SQL.
Run this in your terminal to verify the server starts. Then let us know if it worked - your result helps other developers.
npx -y '@geolens/sdk' 2>&1 | head -1 && echo "✓ Server started successfully"
After testing, let us know if it worked:
Five weighted categories - click any category to see the underlying evidence.
GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data
### Summary Multiple GeoLens read/link endpoints authorized only the resource named in the request URL (a map, a VRT, a source dataset, an AI request) and failed to re-authorize a **second, caller-influenced dataset** that the request reached through a relationship, layer reference, mosaic source, or request body. This "authorize the URL resource, read a *different* dataset un-re-authorized" pattern let callers read data from datasets they have no access to. The most severe instances require *
Click any tool to inspect its schema.
Be the first to review
Have you used this server?
Share your experience - it helps other developers decide.
Sign in to write a review.
Others in other
deja-vu: local memory over the session histories of thirty-five coding agents.
Compress tool outputs, logs, files, and RAG chunks before they reach the LLM. 60-95% fewer tokens, same answers. Library, proxy, MCP server.
Official command-line tool for Reolink IP cameras, doorbells and NVRs — LAN only, no cloud. Snapshots, PTZ, RTSP/RTMP stream URLs, two-way audio (talkback/TTS), motion and AI detection, event monitoring, VOD download. JSON output and a built-in MCP server. Works with Home Assistant, Frigate and go2rtc.
Search PubMed/Europe PMC, fetch articles and full text (PMC/EPMC/Unpaywall), citations, MeSH terms.
MCP Security Weekly
Get CVE alerts and security updates for io.github.geolens-io/geolens and similar servers.
Start a conversation
Ask a question, share a tip, or report an issue.
Sign in to join the discussion.