Reported issues for MITRE ATT&CK
Pod holds 17 of 17 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.
Back to MITRE ATT&CK.
Most discussed
mitre-mcp and mcp http server not working
Hi,
I just tried installing the mitre-mcp server and unfortunately I cannot make it work at all using examples in your repo.
Installation
The module was successfully installed locally with
pip install -r requirements.txt
pip install -e .
but the same behaviors occur when just doing pip install mcp-server.
The version is 0.1.3
Issues
Direct command line use
$ pip install -r requirements.txt
[...]
$ pip install -e .
[...]
Successfully built mitre-mcp…
[Read the thread](https://github.com/Montimage/mitre-mcp/issues/1) · 2025-11-14 · open · external user · 5 comments
### 9.3: Render failures as errors, with Retry
<!-- gitissue:normalized v1 -->
## Type
improvement (high confidence)
## Description
`F-UX-009`: LLM, tool and server failures are returned as a normal string and rendered as an "Assistant" answer with a Copy button; the message is a generic checklist that blames the user's query. Return typed errors, render them as errors, and offer Retry.
**Current state:**
The current state and measured evidence are recorded in the Reporter Context.
**Proposed change:**
Complete the stated plan task…
[Read the thread](https://github.com/Montimage/mitre-mcp/issues/95) · 2026-09-18 · closed · outside contributor · 2 comments
### 8.7: Send compact, capped tool results to the LLM and stop logging payloads
<!-- gitissue:normalized v1 -->
## Type
improvement (high confidence)
## Description
Two performance defects in the frontend agent loop:
- **F-PERF-008** — tool results are re-stringified with `null, 2` indentation (+17 KB on `get_software`) and sent to the LLM uncapped for up to five loop iterations; `conversationHistory` grows unbounded and is re-sent every turn.
- **F-PERF-013** — `this.debug = true` unconditionally in `mcpClient.js`, so whole tool results are logged to the console in…
[Read the thread](https://github.com/Montimage/mitre-mcp/issues/89) · 2026-09-18 · closed · outside contributor · 2 comments
### Add public MCP server with self-service API key registration
<!-- gitissue:normalized v1 -->
## Type
feature (high confidence)
## Description
Offer mitre-mcp as a publicly hosted MCP server that anyone can use for free, instead of requiring a local install and a locally downloaded MITRE ATT&CK dataset.
Users should be able to self-register, receive an API key, and point an MCP client at the hosted endpoint to run the existing MITRE ATT&CK lookups. The free tier is expected to be usage-limited per key so the public deployment stays sustainable.…
[Read the thread](https://github.com/Montimage/mitre-mcp/issues/219) · 2026-09-20 · open · outside contributor · 0 comments
### fix(frontend): HTTPS-hosted UI breaks loopback MCP URLs
## Problem
When the chat UI is served over HTTPS (e.g. GitHub Pages), scheme-relative MCP URLs are upgraded to `https://localhost:8000/mcp`, causing `net::ERR_SSL_PROTOCOL_ERROR`. Users also lack clear guidance for the two-process local dev setup and for why hosted pages cannot reach loopback endpoints.
## Acceptance Criteria
- [ ] Loopback MCP server URLs stay on explicit `http://` when built from host/port (including from an HTTPS page origin).
- [ ] Settings shows a clear warning when a…
[Read the thread](https://github.com/Montimage/mitre-mcp/issues/216) · 2026-09-19 · closed · outside contributor · 0 comments
### Allow any model name for the Google Gemini provider
<!-- gitissue:normalized v1 -->
## Type
improvement (medium confidence)
## Description
The Google Gemini provider currently offers model selection from a fixed, predefined model list. The request is to accept any model name typed by the user instead, the way the OpenRouter provider already does, so the provider does not need a list update every time a Gemini model is released or renamed.
**Current state:**
Choosing a Gemini model is constrained to a predefined list of model names.…
[Read the thread](https://github.com/Montimage/mitre-mcp/issues/213) · 2026-09-19 · closed · outside contributor · 0 comments
### Redesign the landing page and add chat simulation mode
## Summary
Tracking issue for PR #210 — three changes shipped together because they touch the same components:
1. **"Ivory Dossier" design system** — warm editorial palette (paper `#FAF8F4`, ink `#14120E`, brass `#E9AB34` accent) as Tailwind v4 `@theme` tokens, self-hosted variable fonts (Newsreader / Libre Franklin / JetBrains Mono), applied across navbar, hero, features, playbooks, footer, chat, and the settings dialog. Includes two stacking fixes: settings dialog portalled to `<body>` (it…
[Read the thread](https://github.com/Montimage/mitre-mcp/issues/211) · 2026-09-19 · closed · outside contributor · 0 comments
### Add OpenAI-compatible endpoint provider with optional API key
<!-- gitissue:normalized v1 -->
## Type
feature (high confidence)
## Description
The landing page currently lets a user pick from a fixed set of LLM providers, with Ollama as the option for self-hosted models. Add support for a generic **OpenAI-compatible endpoint** so the chat can be pointed at any service that speaks the OpenAI chat-completions API, not only Ollama.
The endpoint must work in both authentication modes: **with an API key** (hosted or key-protected gateways) and **without…
[Read the thread](https://github.com/Montimage/mitre-mcp/issues/209) · 2026-09-19 · closed · outside contributor · 0 comments
## Most recent
### 9.8: Give status and feedback real semantics and plain-language copy
<!-- gitissue:normalized v1 -->
## Type
improvement (high confidence)
## Description
`F-UX-008`: success and error states differ by one step of grey with no icon and no `role="alert"` (`ServerConfig.jsx:446-452`), and chat error bubbles look like system notices (`ChatMessage.jsx:130-137`). `F-UX-016`: status is conveyed by colour alone behind "MCP"/"LLM" labels and a hover `title` (`ChatBox.jsx:289-305`), and the copy is full of jargon ("Using Vite proxy (/mcp) to avoid CORS issues", "O(1)…
[Read the thread](https://github.com/Montimage/mitre-mcp/issues/100) · 2026-09-18 · closed · outside contributor · 0 comments
### 7.8: Give HTTP mode an authentication story
<!-- gitissue:normalized v1 -->
## Type
bug (high confidence)
## Description
`F-SEC-005`: HTTP mode has no authentication (`mitre_mcp_server.py:1183`) while `README.md:141` documents `--host 0.0.0.0`; the data is public, but the endpoint is an open CPU and memory amplifier. Document reverse-proxy authentication for any non-loopback bind and add an optional bearer-token check read from an environment variable.
> **Reporter Context**
> ## 7.8: Give HTTP mode an authentication story
>
> Type:…
[Read the thread](https://github.com/Montimage/mitre-mcp/issues/80) · 2026-09-18 · closed · outside contributor · 0 comments
### 2.10: Recover from an expired MCP session instead of failing until reload
<!-- gitissue:normalized v1 -->
## Type
bug (high confidence)
## Description
`F-BUG-008`: an HTTP 404 (expired session) is handled like any other error (`frontend/src/services/mcpClient.js:198`); `sessionId` is never cleared and `resetSession()` (`:249`) has no callers, so every call fails until reload. The same defect exists at `clients/nodejs/mini-mcp-client.js:160-165`. On 404, re-initialise once and retry. Task 4.6 and Task 4.8 later replace both clients with the official SDK clients;…
[Read the thread](https://github.com/Montimage/mitre-mcp/issues/37) · 2026-09-18 · closed · outside contributor · 0 comments
### 2.9: Normalise LLM response content and add an error boundary
<!-- gitissue:normalized v1 -->
## Type
bug (high confidence)
## Description
`F-BUG-007`: `response.content` is returned un-normalised (`frontend/src/services/langGraphAgent.js:547`) although `:500` shows it may be an array; the renderer then throws and, with no error boundary (`main.jsx:6-10`), the whole page unmounts. Normalise to a string at the agent boundary and wrap the app in an error boundary.
**Current behavior:**
The reported defect remains present.
**Expected behavior:**
The…
[Read the thread](https://github.com/Montimage/mitre-mcp/issues/36) · 2026-09-18 · closed · outside contributor · 0 comments
### 2.8: Make the MCP status dot truthful and unblock the input after clearing a pending approval
<!-- gitissue:normalized v1 -->
## Type
bug (high confidence)
## Description
Two defects in `frontend/src/components/chat/ChatBox.jsx`. `F-BUG-006`: `testConnection()` never throws and its boolean is discarded (`:110`, `:154-155`), so the MCP status dot is always green — branch on the returned value. `F-BUG-010`: clearing the chat while a tool approval is pending removes the card but never resolves the promise from `:229-232` (`:259`), so the input stays disabled until reload — resolve it…
[Read the thread](https://github.com/Montimage/mitre-mcp/issues/35) · 2026-09-18 · closed · outside contributor · 0 comments
### 2.7: Serve the stale cache when a refresh download fails
<!-- gitissue:normalized v1 -->
## Type
bug (high confidence)
## Description
`F-BUG-005`: once the cache is older than one day, any download failure propagates through the lifespan (`mitre_mcp/mitre_mcp_server.py:323`, `:505-507`) and the server will not start offline although usable data is on disk. Serve the stale cache with a warning. (Background refresh is `F-PERF-010`, Task 8.5.)
**Current behavior:**
The reported defect remains present.
**Expected behavior:**
The stated acceptance…
[Read the thread](https://github.com/Montimage/mitre-mcp/issues/34) · 2026-09-18 · closed · outside contributor · 0 comments
### 2.6: Expose Mcp-Session-Id through CORS and tolerate a missing session id in the web client
<!-- gitissue:normalized v1 -->
## Type
bug (high confidence)
## Description
`F-BUG-003`: the CORS middleware sets no `expose_headers` (`mitre_mcp/mitre_mcp_server.py:1137`), so cross-origin `response.headers.get('mcp-session-id')` is `null` and the web client throws (`frontend/src/services/mcpClient.js:103-107`); only the Vite dev-proxy path works. Expose the header on the server and treat a missing id as a stateless server in the client.
**Current behavior:**
The reported defect remains…
[Read the thread](https://github.com/Montimage/mitre-mcp/issues/33) · 2026-09-18 · closed · outside contributor · 0 comments
### 0.1: Declare the mcp SDK pin, drop fastmcp, fix the installer and the README advice
<!-- gitissue:normalized v1 -->
## Type
bug (high confidence)
## Description
`F-DEP-001`: the package declares `fastmcp>=2.0.0` (`requirements.txt:2`, `pyproject.toml:28`) but imports `mcp.server.fastmcp` (`mitre_mcp/mitre_mcp_server.py:27`); today that range resolves to `mcp` 2.2.0, where the module raises `ModuleNotFoundError`. Declare `mcp>=1.28.1,<2` directly and remove `fastmcp` in both manifests. `F-BUG-004`: delete the `pip install "mcp[cli]>=0.1.0,<1.0.0"` line at…
[Read the thread](https://github.com/Montimage/mitre-mcp/issues/11) · 2026-09-18 · closed · outside contributor · 0 comments
### Pre.1: Write the agent-runnable environment notes
<!-- gitissue:normalized v1 -->
## Type
improvement (high confidence)
## Description
Document a complete agent-runnable environment so a later agent can install, configure, build, and test the repository from project documentation alone.
**Current state:**
The contributor documentation does not yet consolidate the reporter-specified agent environment, commands, variable names, and repository etiquette.
**Proposed change:**
Add the requested agent-runnable environment guidance to…
[Read the thread](https://github.com/Montimage/mitre-mcp/issues/8) · 2026-09-18 · closed · outside contributor · 0 comments
The remaining reports are on [the project's issue tracker](https://github.com/Montimage/mitre-mcp/issues).