Skip to main content
Glama
CedricG-dev

VulnerabilityMCPServer

by CedricG-dev

VulnerabilityMCPServer

Test d'un serveur MCP local sur le protocol HTTP, avec un mode d'exposition alternatif en API REST/JSON classique.

Prerequisites

A python version 3.9+ should be installed

NPM should be installed (using NodeJS installation)

Related MCP server: CIRCL CVE SEARCH MCP Server

Set up environment

  1. Clone the Github repo

  2. Create a virtual environment linked to the project

python -m venv <PATH_TO_YOU_VENV_FOLDER>\VulnerabilityMCPServer
  1. Start the virtual environment

<PATH_TO_YOU_VENV_FOLDER>\Scripts\Activate.ps1

Use other script based on your environment type (activate / activate.bat)

  1. Install python packages

pip install -e .

This installs every dependency needed to run the server (either mode) and registers the two CLI commands used below, vuln-db and vuln-server, from the single pyproject.toml manifest.

  1. Build the local vulnerability database

The server reads from a local SQLite database (data/vulnerability.db, git-ignored) that must be built before first use, with the vuln-db CLI:

vuln-db --init

See docs/vuln-db.md for the full CLI reference (flags, environment variables, offline/LOCAL fetch mode, examples).

  1. Launch the server

The vulnerability data can be exposed either over the MCP protocol or as a plain REST/JSON API, chosen at startup with the vuln-server CLI:

vuln-server --mode mcp     # MCP protocol, streamable-http, port 8001
vuln-server --mode rest    # REST/JSON API, port 8080

See docs/vuln-server.md for the full CLI reference: configuration (JSON config file per mode, overridable by CLI flags), available MCP tools / REST routes, and how to test each mode (MCP Inspector / Swagger UI).

Run OpenCode

Now you can run OpenCode in a third terminal.

opencode

you get

OPENCODE

use the command /mcps to list mcp servers

OPENCODE MCP

Now test the following prompt


get info about vulnerability with id  CVE-2025-53770 and trace if you used a mcp server and a tool in your response

We get the following response with local LLM qwen3.6:latest

RESPONSE QWEN

We get the following response with remote Claude Sonnet 5

RESPONS SONNET

Maintenance

ActivityMaintained
ResponsivenessSyncing

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • A
    license
    B
    quality
    D
    maintenance
    A Model Context Protocol (MCP) server for querying the CVE-Search API. This server provides comprehensive access to CVE-Search, browse vendor and product、get CVE per CVE-ID、get the last updated CVEs.
    6
    103
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    MCP server that provides tools to search, filter, and retrieve CVE data from the NVD API, including by ID, keyword, severity, and recency.
    4
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    MCP server to query and manage CISA Known Exploited Vulnerabilities catalog with EPSS overlay, enabling vulnerability checks and remediation deadline tracking.
    MIT

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/CedricG-dev/nvd-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server