mcpm

Install command:
brew install mcpm

Open source, community-driven MCP server and client manager

https://mcpm.sh/

License: MIT

Development: Pull requests

Formula JSON API: /api/formula/mcpm.json

Formula code: mcpm.rb on GitHub

Bottle (binary package) installation support provided for:

macOS on
Apple Silicon
tahoe
sequoia
sonoma
macOS on
Intel
sonoma
Linux ARM64
x86_64

Current versions:

stable 2.15.0

Revision: 2

Depends on:

certifi 2026.7.22 Mozilla CA bundle for Python
cryptography 50.0.1 Cryptographic recipes and primitives for Python
libyaml 0.2.5 YAML Parser
pydantic 2.13.5 Data validation using Python type hints
python@3.14 3.14.7 Interpreted, interactive, object-oriented programming language
rpds-py 2026.6.3 Python bindings to Rust's persistent data structures

Depends on when building from source:

cmake 4.4.3 Cross-platform make
rust 1.98.0 Safe, concurrent, practical language

Binaries: mcpm

Known vulnerabilities in the current version:

GHSA-m8x7-r2rg-vh5g (medium) FastMCP has a Command Injection vulnerability - Gemini CLI
GHSA-5h2m-4q8j-pqpj FastMCP OAuth Proxy token reuse across MCP servers
GHSA-w8v5-vhqr-4h9v DiskCache has unsafe pickle deserialization
GHSA-rww4-4w9c-7733 FastMCP: Missing Consent Verification in OAuth Proxy Callback Facilitates Confused Deputy Vulnera...
GHSA-vv7q-7jx5-f767 (critical) FastMCP OpenAPI Provider has an SSRF & Path Traversal Vulnerability
GHSA-vj7q-gjh5-988w MCP Python SDK: WebSocket server transport does not support Host/Origin validation
GHSA-rcfx-77hg-w2wv FastMCP updated to MCP 1.23+ due to CVE-2025-66416

Data from Homebrew/advisory-database. Run brew vulns mcpm for a live check.

Analytics:

30 days90 days365 days
Installs242722,165
Installs (--HEAD)002
Installs on Request242722,165
Installs on Request (--HEAD)002
Build Errors0