This project is an independent MCP server for Canvas LMS APIs. It is not affiliated with, endorsed by, or maintained by Instructure or Canvas.
In June 2025, during development of this MCP, I identified a Broken Access Control issue in the Canvas environment at bootcampspot.instructure.com. The issue exposed personally identifiable information for other students enrolled in my course.
I reported the issue through Bugcrowd on June 5, 2025, and also contacted Instructure / Canvas security channels directly. The Bugcrowd report was later closed as "Not Applicable." In subsequent correspondence, Instructure stated that the bootcampspot.instructure.com environment was outside its control.
Public references:
- Disclosure thread: https://www.reddit.com/r/cybersecurity/comments/1t6wmkw/reported_a_broken_access_control_bug_to/
- Bugcrowd activity timeline: https://imgur.com/gallery/canvas-vuln-declared-n-11-months-ago-zYfHnBs
- Later Instructure / BootcampSpot correspondence: https://imgur.com/a/BnhgXme
This repository does not publish exploit steps, affected tenant details beyond what is already public, live URLs, screenshots containing student data, or proof-of-concept abuse flows.
Separately, Instructure publicly disclosed a Canvas security incident in May 2026, and public reporting has linked the incident to ShinyHunters claims. This repository makes no claim that the June 2025 report caused, enabled, predicted, or is technically connected to the May 2026 incident.
This disclosure is documented here for project history and transparency only.
A comprehensive Model Context Protocol (MCP) server for Canvas LMS with complete student, instructor, and account administration functionality
- ๐ NEW: Streamable HTTP transport support (
MCP_TRANSPORT=streamable-http) - ๐ฅ๏ธ Preserved: First-class stdio transport for local MCP clients
- ๐งช Added: Behavior tests for lifecycle, transports, and structured failure-path errors
- ๐งฑ Improved: Stricter tool schemas and codemode-oriented tool descriptions
- ๐ง FIXED: Course creation "page not found" error (missing
account_idparameter) - ๐จโ๐ผ Account Management: Complete account-level administration tools
- ๐ Reports & Analytics: Generate and access Canvas account reports
- ๐ฅ User Management: Create and manage users at the account level
- ๐ข Multi-Account Support: Handle account hierarchies and sub-accounts
- โ API Compliance: All endpoints now follow proper Canvas API patterns