Skip to main content
Glama

Osv Get Vulnerability

osv_get_vulnerability
Read-onlyIdempotent

Fetch the full advisory record for an OSV vulnerability ID. Returns the complete record: summary, full details text, CVE aliases, all affected packages and version ranges, fix versions, CVSS severity vectors, CWE weakness IDs, and references. Use when osv_query_package or osv_query_batch returns a vuln ID and you need the full advisory context — eligibility criteria, scope of affected packages, or remediation guidance.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
idYesOne exact, complete OSV advisory ID from any OSV source database, matched case-sensitively. Prefixes include "GHSA-" (GitHub), "PYSEC-" (PyPI), "RUSTSEC-" (Rust), "GO-" (Go), "DSA-"/"DLA-" (Debian), "USN-" (Ubuntu), "RHSA-" (Red Hat), and "CVE-". No wildcards or partial IDs — take IDs from osv_query_package or osv_query_batch results. Example: "GHSA-29mw-wpgm-hmr9".

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
idNoOSV vulnerability ID.
errorNoPresent when the call failed. Absent on success.
cweIdsNoCWE weakness classifications (e.g. ["CWE-79"]). Present on GitHub Advisory Database records; empty otherwise.
aliasesNoAlternative IDs — usually CVE IDs. Accepted by nvd_get_cve on nist-nvd-mcp-server for CVSS base score, EPSS exploitation probability, and CISA KEV status.
detailsNoFull advisory text, typically in Markdown. May include proof-of-concept, reproduction steps, or remediation guidance.
summaryNoOne-line advisory description.
affectedNoAll affected packages and their version ranges. An advisory may span multiple packages or ecosystems.
modifiedNoISO 8601 timestamp of last modification.
severityNoRecord-level severity entries (CVSS vectors, Ubuntu priorities). Empty for unscored advisories and for advisories that score each affected package separately.
publishedNoISO 8601 timestamp when published.
withdrawnNoISO 8601 timestamp when this advisory was withdrawn. Present ONLY on withdrawn advisories — a withdrawn record has been retracted and must not be treated as an active vulnerability.
referencesNoAdvisory references — NVD links, patches, vendor advisories, PoC reports.
schemaVersionNoOSV schema version this record conforms to (e.g. "1.7.3").
severityLabelNoSeverity label ("LOW", "MODERATE", "HIGH", "CRITICAL") from the first source that yields one: database_specific.severity, an Ubuntu priority, then the highest CVSS v3/v4 score (0.1–3.9 LOW, 4.0–6.9 MODERATE, 7.0–8.9 HIGH, 9.0–10.0 CRITICAL). Uses every affected package severity entry when the record-level list is empty. Null when no source yields a label.
severitySourceNoThe severity entry severityLabel was derived from. Null exactly when the label is.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed12 schema fields changed
    • changedInput schema / properties / id / description
      Previous value: -"OSV vulnerability ID. Accepts any prefix: \"GHSA-\" (GitHub), \"PYSEC-\" (Python), \"RUSTSEC-\" (Rust), \"GO-\" (Go), \"DSA-\"/\"DLA-\" (Debian), \"CVE-\" (fallback direct lookups). Example: \"GHSA-29mw-wpgm-hmr9\"."New value: +"One exact, complete OSV advisory ID from any OSV source database, matched case-sensitively. Prefixes include \"GHSA-\" (GitHub), \"PYSEC-\" (PyPI), \"RUSTSEC-\" (Rust), \"GO-\" (Go), \"DSA-\"/\"DLA-\" (Debian), \"USN-\" (Ubuntu), \"RHSA-\" (Red Hat), and \"CVE-\". No wildcards or partial IDs — take IDs from osv_query_package or osv_query_batch results. Example: \"GHSA-29mw-wpgm-hmr9\"."
    • removedInput schema / properties / id / minLength
      Removed value: -1
    • changedInput schema / properties / id / pattern
      Previous value: -"\\S"New value: +"^[A-Za-z][A-Za-z0-9_]*-\\S(.*\\S)?$"
    • changedOutput schema / anyOf
      Previous value: -[
      -  {
      -    "not": {
      -      "required": [
      -        "error"
      -      ]
      -    },
      -    "required": [
      -      "id",
      -      "summary",
      -      "details",
      -      "aliases",
      -      "published",
      -      "modified",
      -      "severity",
      -      "severityLabel",
      -      "affected",
      -      "cweIds",
      -      "references",
      -      "schemaVersion"
      -    ]
      -  },
      -  {
      -    "required": [
      -      "error"
      -    ]
      -  }
      -]New value: +[
      +  {
      +    "not": {
      +      "required": [
      +        "error"
      +      ]
      +    },
      +    "required": [
      +      "id",
      +      "summary",
      +      "details",
      +      "aliases",
      +      "published",
      +      "modified",
      +      "severity",
      +      "severityLabel",
      +      "severitySource",
      +      "affected",
      +      "cweIds",
      +      "references",
      +      "schemaVersion"
      +    ]
      +  },
      +  {
      +    "required": [
      +      "error"
      +    ]
      +  }
      +]
    • changedOutput schema / properties / affected / items / properties / ranges / items / properties / fixed / description
      Previous value: -"First safe version (convenience view — the last \"fixed\" event; see events[])."New value: +"The last \"fixed\" event of this range (convenience view — a multi-interval range carries several; see events[])."
    • addedOutput schema / properties / affected / items / properties / severity
      Added value: +{
      +  "description": "Severity entries scoped to this package. Present only when the advisory scores packages separately; the record-level severity is then empty.",
      +  "items": {
      +    "additionalProperties": false,
      +    "description": "One package-level severity entry.",
      +    "properties": {
      +      "score": {
      +        "description": "CVSS vector string, or the Ubuntu priority (e.g. \"medium\") for type \"Ubuntu\".",
      +        "type": "string"
      +      },
      +      "type": {
      +        "description": "Severity type: \"CVSS_V3\", \"CVSS_V4\", \"CVSS_V2\", or \"Ubuntu\".",
      +        "type": "string"
      +      }
      +    },
      +    "required": [
      +      "type",
      +      "score"
      +    ],
      +    "type": "object"
      +  },
      +  "type": "array"
      +}
    • changedOutput schema / properties / severity / description
      Previous value: -"CVSS severity entries. Empty for unscored advisories."New value: +"Record-level severity entries (CVSS vectors, Ubuntu priorities). Empty for unscored advisories and for advisories that score each affected package separately."
    • changedOutput schema / properties / severity / items / description
      Previous value: -"One CVSS severity entry."New value: +"One record-level severity entry."
    • changedOutput schema / properties / severity / items / properties / score / description
      Previous value: -"CVSS vector string."New value: +"CVSS vector string, or the Ubuntu priority (e.g. \"medium\") for type \"Ubuntu\"."
    • changedOutput schema / properties / severity / items / properties / type / description
      Previous value: -"CVSS version: \"CVSS_V3\", \"CVSS_V4\", or \"CVSS_V2\"."New value: +"Severity type: \"CVSS_V3\", \"CVSS_V4\", \"CVSS_V2\", or \"Ubuntu\"."
    • changedOutput schema / properties / severityLabel / description
      Previous value: -"Human-readable severity label (\"LOW\", \"MODERATE\", \"HIGH\", \"CRITICAL\"). Present on GHSA-sourced records; null when not available."New value: +"Severity label (\"LOW\", \"MODERATE\", \"HIGH\", \"CRITICAL\") from the first source that yields one: database_specific.severity, an Ubuntu priority, then the highest CVSS v3/v4 score (0.1–3.9 LOW, 4.0–6.9 MODERATE, 7.0–8.9 HIGH, 9.0–10.0 CRITICAL). Uses every affected package severity entry when the record-level list is empty. Null when no source yields a label."
    • addedOutput schema / properties / severitySource
      Added value: +{
      +  "anyOf": [
      +    {
      +      "additionalProperties": false,
      +      "properties": {
      +        "computedScore": {
      +          "description": "CVSS score computed from the vector as published: a CVSS 4.0 vector over every metric group it carries (threat and environmental included), a CVSS 3.x vector with its temporal metrics. Present only for CVSS sources.",
      +          "type": "number"
      +        },
      +        "score": {
      +          "description": "The published value the label came from: the database_specific.severity text, the Ubuntu priority, or the CVSS vector.",
      +          "type": "string"
      +        },
      +        "type": {
      +          "description": "Source kind: the database_specific.severity label, an Ubuntu priority, or a CVSS vector.",
      +          "enum": [
      +            "database_specific",
      +            "Ubuntu",
      +            "CVSS_V3",
      +            "CVSS_V4"
      +          ],
      +          "type": "string"
      +        }
      +      },
      +      "required": [
      +        "type",
      +        "score"
      +      ],
      +      "type": "object"
      +    },
      +    {
      +      "type": "null"
      +    }
      +  ],
      +  "description": "The severity entry severityLabel was derived from. Null exactly when the label is."
      +}
  2. Changed2 schema fields changed
    • removedOutput schema / properties / severityLabel / anyOf
      Removed value: -[
      -  {
      -    "type": "string"
      -  },
      -  {
      -    "type": "null"
      -  }
      -]
    • addedOutput schema / properties / severityLabel / type
      Added value: +[
      +  "string",
      +  "null"
      +]
  3. Changed6 schema fields changed
    • changedInput schema / $schema
      Previous value: -"http://json-schema.org/draft-07/schema#"New value: +"https://json-schema.org/draft/2020-12/schema"
    • addedInput schema / additionalProperties
      Added value: +false
    • changedOutput schema / $schema
      Previous value: -"http://json-schema.org/draft-07/schema#"New value: +"https://json-schema.org/draft/2020-12/schema"
    • addedOutput schema / anyOf
      Added value: +[
      +  {
      +    "not": {
      +      "required": [
      +        "error"
      +      ]
      +    },
      +    "required": [
      +      "id",
      +      "summary",
      +      "details",
      +      "aliases",
      +      "published",
      +      "modified",
      +      "severity",
      +      "severityLabel",
      +      "affected",
      +      "cweIds",
      +      "references",
      +      "schemaVersion"
      +    ]
      +  },
      +  {
      +    "required": [
      +      "error"
      +    ]
      +  }
      +]
    • addedOutput schema / properties / error
      Added value: +{
      +  "additionalProperties": {},
      +  "description": "Present when the call failed. Absent on success.",
      +  "properties": {
      +    "code": {
      +      "description": "JSON-RPC error code for this failure.",
      +      "maximum": 9007199254740991,
      +      "minimum": -9007199254740991,
      +      "type": "integer"
      +    },
      +    "data": {
      +      "additionalProperties": {},
      +      "properties": {
      +        "reason": {
      +          "description": "Machine-readable failure mode. Declared by this tool: `vulnerability_not_found`: The requested OSV ID does not exist in the database. Other values are possible when a failure originates below the handler.",
      +          "examples": [
      +            "vulnerability_not_found"
      +          ],
      +          "type": "string"
      +        },
      +        "recovery": {
      +          "additionalProperties": {},
      +          "description": "Actionable next step for the caller.",
      +          "properties": {
      +            "hint": {
      +              "type": "string"
      +            }
      +          },
      +          "required": [
      +            "hint"
      +          ],
      +          "type": "object"
      +        },
      +        "retryable": {
      +          "description": "Whether retrying may succeed.",
      +          "type": "boolean"
      +        }
      +      },
      +      "type": "object"
      +    },
      +    "message": {
      +      "description": "Human-readable description of what went wrong.",
      +      "type": "string"
      +    }
      +  },
      +  "required": [
      +    "code",
      +    "message"
      +  ],
      +  "type": "object"
      +}
    • removedOutput schema / required
      Removed value: -[
      -  "id",
      -  "summary",
      -  "details",
      -  "aliases",
      -  "published",
      -  "modified",
      -  "severity",
      -  "severityLabel",
      -  "affected",
      -  "cweIds",
      -  "references",
      -  "schemaVersion"
      -]
  4. Changed2 schema fields changed
    • addedInput schema / properties / id / minLength
      Added value: +1
    • addedInput schema / properties / id / pattern
      Added value: +"\\S"
  5. Changed9 schema fields changed
    • changedOutput schema / properties / affected / items / properties / ecosystem / description
      Previous value: -"Affected package ecosystem."New value: +"Affected package ecosystem. Empty for source-only advisories."
    • changedOutput schema / properties / affected / items / properties / packageName / description
      Previous value: -"Affected package name."New value: +"Affected package name. Empty for source-only advisories (GIT ranges with no package identity)."
    • addedOutput schema / properties / affected / items / properties / ranges / items / properties / events
      Added value: +{
      +  "description": "Ordered event boundaries defining the affected interval(s) — the loss-free view preserving multiple introduced/fixed pairs the scalar fields collapse.",
      +  "items": {
      +    "additionalProperties": false,
      +    "description": "One ordered range event.",
      +    "properties": {
      +      "type": {
      +        "description": "Event boundary type: \"introduced\", \"fixed\", \"last_affected\", or \"limit\".",
      +        "type": "string"
      +      },
      +      "value": {
      +        "description": "Version string or commit identifier at this boundary.",
      +        "type": "string"
      +      }
      +    },
      +    "required": [
      +      "type",
      +      "value"
      +    ],
      +    "type": "object"
      +  },
      +  "type": "array"
      +}
    • changedOutput schema / properties / affected / items / properties / ranges / items / properties / fixed / description
      Previous value: -"First safe version."New value: +"First safe version (convenience view — the last \"fixed\" event; see events[])."
    • changedOutput schema / properties / affected / items / properties / ranges / items / properties / introduced / description
      Previous value: -"First affected version."New value: +"First affected version (convenience view — the last \"introduced\" event; see events[] for full interval order)."
    • changedOutput schema / properties / affected / items / properties / ranges / items / properties / lastAffected / description
      Previous value: -"Last affected version when no fix exists."New value: +"Last affected version when no fix exists (convenience view — see events[])."
    • addedOutput schema / properties / affected / items / properties / ranges / items / properties / repo
      Added value: +{
      +  "description": "Source repository URL for GIT ranges. Absent on version ranges.",
      +  "type": "string"
      +}
    • addedOutput schema / properties / affected / items / properties / versions
      Added value: +{
      +  "description": "Explicit affected versions enumerated by the advisory. Absent or empty when affected versions are expressed only as ranges.",
      +  "items": {
      +    "description": "An explicitly-listed affected version.",
      +    "type": "string"
      +  },
      +  "type": "array"
      +}
    • addedOutput schema / properties / withdrawn
      Added value: +{
      +  "description": "ISO 8601 timestamp when this advisory was withdrawn. Present ONLY on withdrawn advisories — a withdrawn record has been retracted and must not be treated as an active vulnerability.",
      +  "type": "string"
      +}
  6. First observed

TDQS

A4.7/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint and idempotentHint, and the description adds substantial behavioral detail beyond that: it lists the full advisory fields returned (summary, details, aliases, affected packages, fix versions, CVSS, CWE, references). It also notes the ID must be exact and taken from query results, which is useful operational context.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is two sentences, front-loaded with the action and output, and the usage guidance is clear and efficient. No filler or redundant phrasing; every clause adds value.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With an output schema present, the description does not need to specify return structure further, but it does, which is a bonus. It covers when to use, what to expect, and the source of the input ID. There are no missing critical elements for safe and correct invocation.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%: the id parameter already has a thorough description covering pattern, prefix examples, case-sensitivity, and no-wildcard requirement. The tool description adds no parameter-level meaning beyond restating that the ID is an OSV vulnerability ID, so it neither improves nor detracts from the schema baseline.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a specific verb and resource: 'Fetch the full advisory record for an OSV vulnerability ID.' It then enumerates the complete returned payload and explicitly names the sibling query tools as the source of IDs, clearly distinguishing this retrieval tool from the query tools.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides explicit when-to-use instructions: 'Use when osv_query_package or osv_query_batch returns a vuln ID and you need the full advisory context.' This names the alternatives and the precise condition that selects this tool, leaving no ambiguity.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.