CIRCL CVE SEARCH MCP Server
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@CIRCL CVE SEARCH MCP ServerGet details for CVE-2021-44228"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
CIRCL CVE SEARCH MCP Server
A Model Context Protocol (MCP) server for accessing the CIRCL CVE SEARCH API, providing comprehensive vulnerability and security information.
Features
This MCP server provides reliable tools to access:
CVE Information: Get detailed information about specific Common Vulnerabilities and Exposures
Vendor Browsing: Browse CVEs by vendor name to discover security issues in specific vendors' products
CWE Information: Get Common Weakness Enumeration information for understanding vulnerability types
CAPEC Information: Get Common Attack Pattern Enumeration and Classification data for understanding attack methods
Key Improvements
Retry Logic: Automatic retry with exponential backoff for reliable API calls
Enhanced Formatting: Structured, readable response formatting with key information highlighted
Better Error Handling: Clear, actionable error messages with troubleshooting guidance
Input Validation: Comprehensive validation and sanitization of all inputs
Installation
npm install @cyreslab/circl-cve-search-mcp-serverUsage
Add this server to your MCP client configuration:
{
"mcpServers": {
"circl-cve-search": {
"command": "npx",
"args": ["@cyreslab/circl-cve-search-mcp-server"]
}
}
}Available Tools
get_cve
Get detailed information about a specific CVE by its ID.
Parameters:
cve_id(required): CVE identifier (e.g., "CVE-2021-44228")
Example:
{
"name": "get_cve",
"arguments": {
"cve_id": "CVE-2021-44228"
}
}Response Format:
Structured CVE data with key information highlighted
Summary, publication dates, CVSS scores
Associated weakness types (CWE) and reference counts
Full raw data for detailed analysis
browse_vendor
Browse CVEs by vendor name to discover security issues in specific vendors' products.
Parameters:
vendor(required): Vendor name (e.g., "apache", "microsoft", "google")limit(optional): Number of results to return (default: 10, max: 50)
Example:
{
"name": "browse_vendor",
"arguments": {
"vendor": "apache",
"limit": 15
}
}Response Format:
List of CVEs for the specified vendor
Total count and displayed count
Vendor name normalization
get_cwe
Get Common Weakness Enumeration (CWE) information by ID.
Parameters:
cwe_id(required): CWE identifier (e.g., "CWE-79", "CWE-89")
Example:
{
"name": "get_cwe",
"arguments": {
"cwe_id": "CWE-79"
}
}Response Format:
CWE name and detailed description
Extended descriptions and weakness ordinalities
Likelihood of exploit information
Full raw data for comprehensive analysis
get_capec
Get Common Attack Pattern Enumeration and Classification (CAPEC) information by ID.
Parameters:
capec_id(required): CAPEC identifier (e.g., "CAPEC-66", "CAPEC-89")
Example:
{
"name": "get_capec",
"arguments": {
"capec_id": "CAPEC-66"
}
}Response Format:
Attack pattern name and description
Typical severity and likelihood of attack
Prerequisites and related weaknesses
Complete raw data for in-depth analysis
Data Source
This server uses the CIRCL CVE SEARCH API, which provides:
Comprehensive CVE data from the National Vulnerability Database (NVD)
Common Platform Enumeration (CPE) information
Common Weakness Enumeration (CWE) data
Common Attack Pattern Enumeration and Classification (CAPEC) data
Regular updates with the latest vulnerability information
Rate Limiting
The CIRCL CVE SEARCH API is free to use and doesn't require authentication. However, please use it responsibly and avoid making excessive requests that could impact the service.
Error Handling
The server handles various error conditions:
Invalid CVE/CWE/CAPEC ID formats
Empty search queries
API rate limiting
Network errors
Invalid parameters
Development
Building
npm run buildRunning in Development
npm run devLicense
MIT License - see LICENSE file for details.
Contributing
Contributions are welcome! Please feel free to submit a Pull Request.
Support
For issues and questions:
GitHub Issues: Report an issue
CIRCL CVE SEARCH API Documentation: https://cve.circl.lu/api/
This server cannot be installed
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Latest Blog Posts
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/Cyreslab-AI/circl-cve-search-mcp-server'
If you have feedback or need assistance with the MCP directory API, please join our Discord server