Context7 attacks one of the most common failures of AI coding tools: answers based on a library as it looked in the model's training data. When your agent needs to use Next.js, Supabase or a Cloudflare Worker API, Context7 looks up the library in its index and returns current documentation and code examples for the version you name, which the agent reads before it writes code. It works either as an MCP server with two tools (resolve-library-id and query-docs) or as a ctx7 command-line tool driven by a skill, and one setup command configures Claude Code, Cursor or OpenCode.
It is made by Upstash, the serverless database company, and has about 63,000 stars and a long run of TikTok and YouTube videos recommending it as an essential MCP server. The repository is MIT-licensed, but it contains the client side only: the MCP server, CLI and SDKs. The documentation index, parser and crawler behind mcp.context7.com are private, and library entries are community-submitted.
- Repository: github.com/upstash/context7
- Licence: MIT (MIT License)
- Language: TypeScript. Stars: 62.6K. Forks: 3,044. Last push: Oct 2, 2026.
- Scan: safe, Oct 2, 2026, commit bfa02ea
Who it is for
Developers who use Claude Code, Cursor, Codex or similar agents with fast-moving frameworks and are tired of fixing code written against last year's API.
Getting started
1. Set up Context7 for your agent (Node.js 18+); signs in with OAuth and creates an API key
npx ctx7 setup2. Target a specific agent if you use more than one
npx ctx7 setup --claude3. Then ask for docs in a prompt
How do I set up Next.js 14 middleware? use context7Your queries go to Upstash's hosted service at mcp.context7.com; nothing about the lookup runs locally. The ctx7 CLI also sends anonymous setup and install events unless you set CTX7_TELEMETRY_DISABLED=1. To undo the setup, run npx ctx7 remove. Manual MCP configuration for 30-plus clients is documented at context7.com.
Safety scan
We cloned upstash/context7 at commit bfa02ea on Oct 2, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.
- One secret candidate in 502 files and about 51,000 lines: a Kubernetes example in docs/enterprise/integrations/other-git.mdx whose private key body is literally "...". No pattern hits, no committed binaries, no bare-IP URLs and no install hooks.
- We read the network code. packages/cli/src/utils/tracking.ts posts setup, install and upgrade events (which agents you configured, the auth mode) to context7.com/api/v2/cli/events, skipped when CTX7_TELEMETRY_DISABLED is set or you point the CLI at another server. The MCP server's OpenTelemetry Prometheus exporter only loads when explicitly enabled for HTTP deployments and exposes metrics locally rather than sending them anywhere.
- pnpm-lock.yaml pins 839 packages with 144 known advisories, none critical and 61 high. Most are denial-of-service issues in build and lint tooling (brace-expansion, minimatch, js-yaml); the runtime-adjacent ones are fast-uri and hono in the server stack and figlet in the CLI's banner.
- Six workflows, none using pull_request_target; none of the 10 third-party actions is pinned to a commit. Security policy, Dependabot and licence present; no CodeQL or contributing guide.
What the scanner counted
| Check | Result |
|---|---|
| Secrets | 1 candidate found and read; see the notes above. |
| Suspicious code | None found. |
| Install-time code | None: nothing runs at install beyond the package manager itself. |
| Committed binaries | None. |
| CI workflows | 6 workflows. None use pull_request_target. 10 of 10 third-party actions pinned to a tag rather than a commit. |
| Network hosts | 27 distinct hosts referenced from source; most often mcp.context7.com, context7.internal.example, other.com, context7.com. No URLs to bare IP addresses. |
| Known vulnerabilities | 144 advisories across 839 pinned packages: 0 critical, 61 high, 68 moderate, 15 low. pnpm-lock.yaml: 839 packages, 144 advisories. |
| Project hygiene | Has security policy, automated dependency updates, licence file. Missing CodeQL, contributing guide. |
| OpenSSF Scorecard | Not scored: the project is not in Scorecard's weekly index. |
The raw findings
Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.
Secret candidates (1, redacted)
| Where | Rule | Match |
|---|---|---|
| docs/enterprise/integrations/other-git.mdx:71 | private-key | -----B…--- (35 chars) |
Worst known vulnerabilities (24 of 144)
| Advisory | Severity | Package | Summary |
|---|---|---|---|
| GHSA-jfgx-wxx8-mp94 | high | @earendil-works/pi-coding-agent@0.78.0 | Pi Agent: Predictable temporary extension install paths allow local privilege escalation on shared Linux hosts |
| GHSA-3jxr-9vmj-r5cp | high | brace-expansion@1.1.15 | brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups |
| GHSA-6j4f-fj2g-mc7p | high | brace-expansion@1.1.15 | brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion |
| GHSA-mh99-v99m-4gvg | high | brace-expansion@1.1.15 | brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash |
| GHSA-qhr7-859c-m2p7 | high | brace-expansion@1.1.15 | brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion |
| GHSA-rgw5-rvv9-x895 | high | brace-expansion@1.1.15 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation |
| GHSA-3jxr-9vmj-r5cp | high | brace-expansion@2.0.2 | brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups |
| GHSA-6j4f-fj2g-mc7p | high | brace-expansion@2.0.2 | brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion |
| GHSA-mh99-v99m-4gvg | high | brace-expansion@2.0.2 | brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash |
| GHSA-qhr7-859c-m2p7 | high | brace-expansion@2.0.2 | brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion |
| GHSA-rgw5-rvv9-x895 | high | brace-expansion@2.0.2 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation |
| GHSA-3jxr-9vmj-r5cp | high | brace-expansion@5.0.6 | brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups |
| GHSA-6j4f-fj2g-mc7p | high | brace-expansion@5.0.6 | brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion |
| GHSA-mh99-v99m-4gvg | high | brace-expansion@5.0.6 | brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash |
| GHSA-qhr7-859c-m2p7 | high | brace-expansion@5.0.6 | brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion |
| GHSA-rgw5-rvv9-x895 | high | brace-expansion@5.0.6 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation |
| GHSA-vfj7-8cjw-p6xm | high | braces@3.0.3 | braces vulnerable to stack-exhaustion denial of service through deeply nested patterns |
| GHSA-4c8g-83qw-93j6 | high | fast-uri@3.1.0 | fast-uri vulnerable to host confusion via failed IDN canonicalization |
| GHSA-7p8r-x3mc-p8w7 | high | fast-uri@3.1.0 | fast-uri vulnerable to host confusion via backslash authority introducer |
| GHSA-f65p-4m7j-42xc | high | fast-uri@3.1.0 | fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization |
| GHSA-jqff-g426-hqxp | high | fast-uri@3.1.0 | fast-uri vulnerable to host confusion via percent-encoded scheme normalization |
| GHSA-q3j6-qgpj-74h6 | high | fast-uri@3.1.0 | fast-uri vulnerable to path traversal via percent-encoded dot segments |
| GHSA-qw65-cvwx-89v3 | high | fast-uri@3.1.0 | fast-uri vulnerable to authority injection via an unvalidated port in serialize |
| GHSA-v2hh-gcrm-f6hx | high | fast-uri@3.1.0 | fast-uri vulnerable to host confusion via literal backslash authority delimiter |
By the numbers
| Stars | 62.6K |
|---|---|
| Forks | 3,044 |
| Contributors | 132 |
| Commits | 1,000 |
| Open issues | 34 |
| Open pull requests | 58 |
| Releases | 128 |
| Latest release | @upstash/context7-opencode@0.2.0 |
| Licence | MIT |
| Main language | TypeScript |
| Project age | 1 year |
| Last push | Oct 2, 2026 |
| Tracked files | 502 |
| Lines of code | 50.9K |
| Checkout size | 25 MB |
Lines by language: Markdown 25.8K, TypeScript 21.6K, JSON 2,441, YAML 709, JavaScript 384.
Questions
Is Context7 free?
The client is MIT-licensed, and the hosted service has a free plan of 1,000 API calls a month for public libraries, with 20 bonus calls a day once you hit the limit. Pro is $10 per seat a month with 2,000 calls per seat and private repositories, extra calls at $5 per 1,000, and Enterprise adds SSO and self-hosting.
Does Context7 see my code?
It sees the queries your agent sends: the library name and the question it is trying to answer, which can describe what you are building. It does not read your files. If that matters, review what your agent passes in the query, or use the Enterprise self-hosted option.
Can I trust the docs Context7 returns?
Mostly, with care. Libraries are indexed from their own repositories and sites, but entries are community-contributed and Upstash says it cannot guarantee their accuracy or security. Prefer library IDs from the official project (for example /vercel/next.js) and report anything suspicious.
This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.
