Skip to main content
Glama
CedricG-dev

VulnerabilityMCPServer

by CedricG-dev

VulnerabilityMCPServer

Test d'un serveur MCP local sur le protocol HTTP

Prerequisites

A python version 3.9+ should be installed

NPM should be installed (using NodeJS installation)

Related MCP server: CIRCL CVE SEARCH MCP Server

Set up environment

  1. Clone the Github repo

  2. Unzip vulnerability.zip in data folder

  3. Create a virtual environement linked to the project

python -m venv <PATH_TO_YOU_VENV_FOLDER>\VulnerabilityMCPServer
  1. Start virtual environement

<PATH_TO_YOU_VENV_FOLDER>\Scripts\Activate.ps1

Use other script based on you environment type (activate / activate.bat)

  1. Install python packages

pip install -r requirements.txt
  1. Launch the MCP server

python src/vulnerability-mcp-server.py

The terminal should render:

SERVER START

Test MCP server

Open another terminal and launch the command

npx @modelcontextprotocol/inspector

if a prompt ask you if you want to install the package accept

Now a browser is opened and display MCP inspector

MCP INSPECTOR

Click on Add Servers ans select + Add manually

Set VULN-SERVER as Server ID

Select streamable-httpas Transport

Set URL with http://localhost:8000/mcp and click on Add

A new serevr appears:

MCP INSPECTOR

Toogle on Conction button at the top-right of the server card

Some info should appear on a right side bar.

Click on Tools and select get_vulnerability_data.

TOOL PICTURES

Fille cve_-_id with for example CVE-2025-53770

RESULT

Run OpenCode

Now you can run OpenCode in a third terminal.

opencode

you get

OPENCODE

use the command /mcps to list mcp servers

OPENCODE MCP

Now test the following prompt


get info about vulnerability with id  CVE-2025-53770 and trace if you used a mcp server and a tool in your response

We get the following response with local LLM qwen3.6:latest

RESPONSE QWEN

We get the following response with remote Claude Sonnet 5

RESPONS SONNET

F
license - not found
-
quality - not tested
C
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    B
    quality
    D
    maintenance
    A Model Context Protocol (MCP) server for querying the CVE-Search API. This server provides comprehensive access to CVE-Search, browse vendor and product、get CVE per CVE-ID、get the last updated CVEs.
    Last updated
    6
    102
    MIT
  • A
    license
    -
    quality
    D
    maintenance
    A Model Context Protocol (MCP) server for querying the NIST National Vulnerability Database (NVD) API, enabling search and retrieval of CVE details, temporal context, and KEV catalog entries.
    Last updated
    13
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    MCP server that provides tools to search, filter, and retrieve CVE data from the NVD API, including by ID, keyword, severity, and recency.
    Last updated
    4
    MIT

View all related MCP servers

Related MCP Connectors

  • MCP server for ScanMalware.com URL scanning, malware detection, and analysis.

  • Security scanner for MCP servers. Detect vulnerabilities, prompt injection, and tool poisoning.

  • MCP server providing access to the Scorecard API to evaluate and optimize LLM systems.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/CedricG-dev/VulnerabilityMCPServer'

If you have feedback or need assistance with the MCP directory API, please join our Discord server