CVE MCP Server

An MCP server that gives the agent vulnerability triage: NVD data, EPSS, the CISA KEV catalog, MITRE ATT&CK mapping and one-call CVE risk scoring

MCP server

Medium risk

We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.

Why this level

  • Makes outbound requests to external vulnerability intelligence APIs
  • Reads API keys from the environment for some tools
All reasons and checks

mukul975/cve-mcp-server

Install

Manual install

git clone https://github.com/mukul975/cve-mcp-server.git
cd cve-mcp-server
python -m venv venv && source venv/bin/activate
pip install -e .

Requires Python 3.10 or newer. Copy optional API keys from .env.example into .env.

This is third-party code. Review the repository files before installing.

What it does

The server connects Claude Desktop or Claude Code to a set of vulnerability and threat triage tools. It pulls a CVE record from NVD, the EPSS exploitation probability, the status in the CISA KEV catalog of actively exploited vulnerabilities, MITRE ATT&CK and CWE mappings, public PoC availability and patch guidance. A dedicated triage_cve tool queries sources in parallel, computes a composite risk score with a hard override for KEV, and falls back to a backup source when NVD is throttled. It also scans dependencies against OSV.dev, parses a CVSS vector, generates reports and prioritizes a list of CVEs. Several tools work with no keys; network and threat intelligence tools need free API keys. All traffic is outbound and private addresses are blocked from lookups.

Who it is for. For security engineers, devsecops and developers who need to quickly gauge how dangerous a CVE is and prioritize patching.

Good fit when

  • You need to know whether a CVE is exploited and how urgent the patch is
  • You need to prioritize a list of CVEs by composite risk score
  • You need to check project dependencies for known vulnerabilities

Not a fit when

  • You want offensive actions against a target rather than vulnerability lookups
  • You need a one-off answer without installing a local server

Example request

Check CVE-2021-44228: is it actively exploited and should we patch it right away

Limitations

Eight tools work without keys: EPSS, CISA KEV, OSV.dev, MITRE ATT&CK, CWE, CVSS parsing, Ransomwhere and NVD at a reduced rate. Without an NVD key the limit is five requests per thirty seconds, so a key is recommended. The IP, Shodan, VirusTotal and GreyNoise tools are unavailable without their free keys. Install is from the repository via pip install -e .; the README lists no separate PyPI package. Python 3.10 or newer is required.

How to disable. Remove the cve-mcp entry from the mcpServers block in your client config. You can delete the virtual environment and repo clone separately; the cache and log live in the ~/.cve-mcp directory.

MCP

Transport
stdio, http
Authentication
not required
Environment variables
Environment variables
NVD_API_KEY
secret
NVD key, raises the request limit from five to fifty per thirty seconds.
GITHUB_TOKEN
secret
GitHub token for advisory and public PoC search, raises the limit from sixty to five thousand requests per hour.
ABUSEIPDB_KEY
secret
AbuseIPDB key, needed for IP reputation lookups.
VIRUSTOTAL_KEY
secret
VirusTotal key, needed for hash, URL, domain and IP checks.
GREYNOISE_API_KEY
secret
GreyNoise key, needed for IP scan activity checks.
SHODAN_KEY
secret
Shodan key, needed for host, port and service reconnaissance.
URLSCAN_KEY
secret
URLScan.io key, extends URL and domain checks.

Security check

  • Makes outbound requests to external vulnerability intelligence APIs
  • Reads API keys from the environment for some tools

README in short

The README frames the server as a way to replace dozens of open tabs across NVD, EPSS, CISA KEV, Shodan and VirusTotal with one question to the agent. It covers the tool catalog, install via pip or uv, key setup across three priority tiers and a keyless quick start. It details the triage_cve tool, the composite risk formula, data sources, privacy and common issues. The default transport is stdio, with streamable-HTTP available for containers via the MCP_TRANSPORT variable. It keeps a SQLite cache and audit log in the ~/.cve-mcp directory.

FAQ

Do I need API keys to start?

No. Eight tools work without keys, including NVD at a reduced rate, EPSS and CISA KEV. Keys add speed and the network tools.

Is this an attack tool?

No. The server is defensive: it gathers reference data on vulnerabilities and threats, all traffic is outbound and private addresses are blocked from lookups.

Editors’ pick

A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor

SkillMedium riskNo VPN needed22.6KRepository stars
Editors’ pick

NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference

CLIHigh risk22.6KRepository stars
Editors’ pick

Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install

CLIMedium riskNo VPN needed18.5KRepository stars
Official

Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents

CLIMedium risk16.8KRepository stars
Foxx AICVE MCP Server

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.