Skip to main content
Glama
CrypKaChu

CVE MCP Server

by CrypKaChu
README.md
# CVE MCP Server

A Model Context Protocol (MCP) server that provides CVE vulnerability lookup and search capabilities using the National Vulnerability Database (NVD).

## Features

- **CVE Lookup**: Get detailed information about specific CVEs by ID
- **CVE Search**: Search for CVEs by keyword in descriptions
- **NVD Integration**: Uses the official NVD API for up-to-date vulnerability data
- **CVSS Scoring**: Provides CVSS v2 and v3 scores and severity ratings

## Prerequisites

- Python 3.13+
- [uv](https://docs.astral.sh/uv/) package manager
- NVD API key (optional but recommended for higher rate limits)

## Installation

### Local Installation

1. **Clone or navigate to the project directory:**
   ```bash
   cd /path/to/cve-mcp-server
   ```

2. **Install dependencies:**
   ```bash
   uv sync
   ```

5. **Set up NVD API key (optional):**
   ```bash
   export NVD_API_KEY="your_nvd_api_key_here"
   ```

## Running the Server

### Local Installation
```bash
# Direct execution
uv run python server.py
```

## MCP Client Configuration

### For Claude Desktop

```json
{
  "mcpServers": {
    "cve-lookup": {
      "command": "uv",
      "args": ["run", "--directory", "/path/to/cve-mcp-server", "python", "server.py"],
      "env": {
        "NVD_API_KEY": "your_nvd_api_key_here"
      }
    }
  }
}
```

## Available Tools

### get_cve(cve_id: str)
Retrieve detailed information about a specific CVE.

**Parameters:**
- `cve_id`: The CVE identifier (e.g., "CVE-2021-44228")

**Returns:**
- CVE ID, description, published date, CVSS scores, severity, CWE, and references

### search_cve(keyword: str, limit: int = 10)
Search for CVEs by keyword in descriptions.

**Parameters:**
- `keyword`: Search term to find in CVE descriptions
- `limit`: Maximum number of results (default 10, max 50)

**Returns:**
- List of matching CVEs with IDs, descriptions, severity, scores, and publication dates

## Usage Examples

Once the MCP server is running and connected to your client:

- "Look up CVE-2021-44228" (Log4Shell vulnerability)
- "Search for CVEs related to Apache Log4j"
- "Find vulnerabilities in WordPress"
- "Get details for CVE-2023-1234"

## Troubleshooting

### Server Not Starting (Red Dot)
1. **Check dependencies:**
   ```bash
   uv sync
   ```

2. **Test server manually:**
   ```bash
   uv run python server.py
   ```

3. **Verify Python path:**
   ```bash
   which python3
   ```

4. **Check MCP configuration syntax** in your config file

### Common Issues

- **ModuleNotFoundError**: Run `uv sync` to install dependencies
- **Permission denied**: Check file permissions and Python path
- **Connection failed**: Restart your MCP client (Claude Desktop)
- **API rate limits**: Set up NVD API key for higher limits

### Configuration Tips

- Use absolute paths in MCP configuration
- Ensure the working directory is correct
- Set environment variables properly
- Restart the MCP client after configuration changes


## Dependencies

- `mcp[cli]>=1.16.0` - Model Context Protocol framework
- `nvdlib>=0.8.3` - NVD API client library
- `requests>=2.32.5` - HTTP requests library

## API Key Setup

1. **Get NVD API Key:**
   - Visit: https://nvd.nist.gov/developers/request-an-api-key
   - Register for a free API key

2. **Set Environment Variable:**
   ```bash
   export NVD_API_KEY="your_api_key_here"
   ```

3. **Update MCP Configuration:**
   Add the API key to your MCP server environment variables

### Testing

### Local Testing
```bash
# Test server imports
uv run python -c "import server; print('Server imports successfully')"

# Test server execution
uv run python server.py
```

## License

This project is open source. See the project files for specific license information.