EPSS MCP Server
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@EPSS MCP ServerGet EPSS score for CVE-2024-12345"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
1. EPSS MCP Server
Note: The major design of code in this repository is based on EPSS-MCP.
2. Features
EPSS MCP Server provides the following features:
Retrieve vulnerability details (including description, CWE, and CVSS scores) from the NVD API, and EPSS scores and percentiles from the EPSS API.
Retrieve EPSS scores for multiple CVEs.
Retrieve the EPSS time series data for a single CVE.
Retrieve the top N CVEs with the highest EPSS scores.
3. Run MCP Server on Docker
Note: If you want to change transport type, edit Dockerfile like this.
# Stdio transport(Default)
CMD ["python3", "epss_mcp.py", "--transport", "stdio"]
# SSE transport
CMD ["python3", "epss_mcp.py", "--transport", "sse"]
# Streamable HTTP transport
CMD ["python3", "epss_mcp.py", "--transport", "http"]Build docker image
cd epss-mcp
docker build -t epss-mcp .Run MCP server
# Stdio transport
docker run --rm -i epss-mcp
# SSE transport (Access from localhost only is recommended)
docker run -d -p 127.0.0.1:8000:8000 epss-mcp
# Streamable HTTP transport (Access from localhost only is recommended)
docker run -d -p 127.0.0.1:8000:8000 epss-mcp4. Installation
4.1. Stdio
Prepare a Python virtual environment using uv. See uv for more details.
curl -LsSf https://astral.sh/uv/install.sh | shuv sync
. .venv/bin/activateCursor, Windsurf
{
"mcpServers": {
"epss-mcp": {
"command": "docker",
"args": [
"run",
"--rm",
"-i",
"epss-mcp"
]
}
}
}Related MCP server: CVE Intelligence MCP Server
4.2. Streamable HTTP, SSE
Cursor
{
"mcpServers": {
"epss-mcp": {
"url": "http://localhost:8000/mcp"
}
}
}Windsurf
serverUrl is your server URL or IP address.
{
"mcpServers": {
"epss-mcp": {
"serverUrl": "http://localhost:8000/sse"
}
}
}Windsurf supports two transport types for MCP servers: stdio and /sse https://docs.windsurf.com/windsurf/cascade/mcp
5. Tool Examples
This example is simply demonstrating how each function works, so it's executed using a Python script as the MCP client. (You can use them via an LLM through editors like Cursor or Windsurf.)
Note: MCP client for testing purposes. (Gemini API Key required)
export GOOGLE_API_KEY=<your api key>Start the MCP server with stdio transport
$ uv run client/client.py epss-mcp/epss_mcp.py
Connected to server with tools: ['get_cve_info', 'top_epss_cves']
MCP Client Started!
Type your queries or `quit` to exit.
Query: 5.1. Get EPSS Score of single CVE
Query: Get EPSS of CVE-2025-33053
> Thinking...
[Calling tool get_cve_info with args {'cve_id': 'CVE-2025-33053'}]
The EPSS score for CVE-2025-33053 is 0.41763, and the percentile is 97.264.5.2. Get EPSS Score of multiple CVEs
Query: Get EPSS of CVE-2025-33053, CVE-2025-21298
> Thinking...
[Calling tool get_cve_info with args {'cve_id': 'CVE-2025-33053,CVE-2025-21298'}]
CVE-2025-33053 has an EPSS score of 0.41763 and is in the 97.264 percentile. CVE-2025-21298 has an EPSS score of 0.70558 and is in the 98.593 percentile.5.3. Get EPSS Score of multiple CVEs with time series
Query: Get time series of CVE-2025-33053 with table format
> Thinking...
[Calling tool get_cve_info with args {'cve_id': 'CVE-2025-33053', 'time_series': True}]
Here is the time series data for CVE-2025-33053 in a table format:
| Date | EPSS | Percentile |
|------------|------------|------------|
| 2025-07-07 | 0.417630000 | 0.972650000 |
| 2025-07-06 | 0.37155000 | 0.96976000 |
| 2025-07-01 | 0.32398000 | 0.96662000 |
| 2025-06-30 | 0.30219000 | 0.96437000 |
| 2025-06-23 | 0.15008000 | 0.94213000 |
| 2025-06-18 | 0.16497000 | 0.94551000 |
| 2025-06-16 | 0.18266000 | 0.94860000 |
| 2025-06-15 | 0.32831000 | 0.96637000 |
| 2025-06-13 | 0.27895000 | 0.96193000 |
| 2025-06-12 | 0.53232000 | 0.97806000 |
| 2025-06-11 | 0.54359000 | 0.97862000 |5.4. Get top 5 CVEs with the highest EPSS scores
uv run client_stdio.py ../epss-mcp/epss_mcp.py --top_n 5
> Thinking...
[Calling tool top_epss_cves with args {'top_n': 5}]
Here are the top 5 CVEs with the highest EPSS scores:
CVE-2023-42793, EPSS score: 0.94584, EPSS percentile: 100.0
CVE-2024-27198, EPSS score: 0.94577, EPSS percentile: 100.0
CVE-2023-23752, EPSS score: 0.94532, EPSS percentile: 100.0
CVE-2024-27199, EPSS score: 0.94489, EPSS percentile: 99.99900000000001
CVE-2018-7600, EPSS score: 0.94489, EPSS percentile: 99.999000000000016. Reference
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Alicense-qualityCmaintenanceEnables CVE lookups and risk assessment by integrating CISA Known Exploited Vulnerabilities (KEV) data and CVSS metrics. It helps users prioritize patching efforts by ranking vulnerabilities based on exploitation status and calculated risk scores.Last updatedMIT
- Alicense-qualityDmaintenanceProvides multi-source vulnerability intelligence for AI-powered security operations, combining NVD CVSS, CISA KEV, and EPSS scores without requiring an API key.Last updated1MIT
- Alicense-qualityAmaintenanceProvides CVE search enriched with EPSS exploit likelihood and CISA KEV status, plus live IP/domain reputation and a real-time threat feed for AI agents.Last updatedMIT
- AlicenseAqualityCmaintenanceProvides live CVE data from NVD and EPSS without API key, enabling AI assistants to look up CVSS scores, search vulnerabilities, and check product CVEs.Last updated3MIT
Related MCP Connectors
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
CVE lookup via NIST NVD, CISA KEV, EPSS, and MITRE ATT&CK. 7 tools.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/kodamap/epss_mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server