CVE MCP Server
by CrypKaChu
README.md
# CVE MCP Server
A Model Context Protocol (MCP) server that provides CVE vulnerability lookup and search capabilities using the National Vulnerability Database (NVD).
## Features
- **CVE Lookup**: Get detailed information about specific CVEs by ID
- **CVE Search**: Search for CVEs by keyword in descriptions
- **NVD Integration**: Uses the official NVD API for up-to-date vulnerability data
- **CVSS Scoring**: Provides CVSS v2 and v3 scores and severity ratings
## Prerequisites
- Python 3.13+
- [uv](https://docs.astral.sh/uv/) package manager
- NVD API key (optional but recommended for higher rate limits)
## Installation
### Local Installation
1. **Clone or navigate to the project directory:**
```bash
cd /path/to/cve-mcp-server
```
2. **Install dependencies:**
```bash
uv sync
```
5. **Set up NVD API key (optional):**
```bash
export NVD_API_KEY="your_nvd_api_key_here"
```
## Running the Server
### Local Installation
```bash
# Direct execution
uv run python server.py
```
## MCP Client Configuration
### For Claude Desktop
```json
{
"mcpServers": {
"cve-lookup": {
"command": "uv",
"args": ["run", "--directory", "/path/to/cve-mcp-server", "python", "server.py"],
"env": {
"NVD_API_KEY": "your_nvd_api_key_here"
}
}
}
}
```
## Available Tools
### get_cve(cve_id: str)
Retrieve detailed information about a specific CVE.
**Parameters:**
- `cve_id`: The CVE identifier (e.g., "CVE-2021-44228")
**Returns:**
- CVE ID, description, published date, CVSS scores, severity, CWE, and references
### search_cve(keyword: str, limit: int = 10)
Search for CVEs by keyword in descriptions.
**Parameters:**
- `keyword`: Search term to find in CVE descriptions
- `limit`: Maximum number of results (default 10, max 50)
**Returns:**
- List of matching CVEs with IDs, descriptions, severity, scores, and publication dates
## Usage Examples
Once the MCP server is running and connected to your client:
- "Look up CVE-2021-44228" (Log4Shell vulnerability)
- "Search for CVEs related to Apache Log4j"
- "Find vulnerabilities in WordPress"
- "Get details for CVE-2023-1234"
## Troubleshooting
### Server Not Starting (Red Dot)
1. **Check dependencies:**
```bash
uv sync
```
2. **Test server manually:**
```bash
uv run python server.py
```
3. **Verify Python path:**
```bash
which python3
```
4. **Check MCP configuration syntax** in your config file
### Common Issues
- **ModuleNotFoundError**: Run `uv sync` to install dependencies
- **Permission denied**: Check file permissions and Python path
- **Connection failed**: Restart your MCP client (Claude Desktop)
- **API rate limits**: Set up NVD API key for higher limits
### Configuration Tips
- Use absolute paths in MCP configuration
- Ensure the working directory is correct
- Set environment variables properly
- Restart the MCP client after configuration changes
## Dependencies
- `mcp[cli]>=1.16.0` - Model Context Protocol framework
- `nvdlib>=0.8.3` - NVD API client library
- `requests>=2.32.5` - HTTP requests library
## API Key Setup
1. **Get NVD API Key:**
- Visit: https://nvd.nist.gov/developers/request-an-api-key
- Register for a free API key
2. **Set Environment Variable:**
```bash
export NVD_API_KEY="your_api_key_here"
```
3. **Update MCP Configuration:**
Add the API key to your MCP server environment variables
### Testing
### Local Testing
```bash
# Test server imports
uv run python -c "import server; print('Server imports successfully')"
# Test server execution
uv run python server.py
```
## License
This project is open source. See the project files for specific license information.
This server cannot be deployed
Maintenance
ActivityInactive
ResponsivenessNo issues