Skip to main content
Glama
SOCTeam-ai

NVD CVE MCP Server

by SOCTeam-ai

NVD CVE MCP Server

npm version License: MIT

A Model Context Protocol (MCP) server for retrieving and displaying CVE vulnerability information from the National Vulnerability Database (NVD). Features dual data sources with NVD API and web scraping fallback.

โœจ Features

  • ๐Ÿ” CVE Details Lookup: Retrieve complete vulnerability information by CVE ID

  • ๐Ÿ”Ž Keyword Search: Search for CVE vulnerabilities by keywords

  • ๐Ÿ“Š Formatted Output: Display vulnerability information in elegant Markdown format

  • ๐Ÿ”„ Dual Data Sources: API-first approach with web scraping as fallback

  • ๐ŸŒ Multi-language Support: Full support for both English and Chinese

Related MCP server: cve-lookup-mcp

๐Ÿ“ฆ Installation

Prerequisites

  • Node.js >= 18.0.0

  • npm or yarn

No installation required! Use directly with npx:

{
  "mcpServers": {
    "nvd-cve": {
      "command": "npx",
      "args": ["-y", "nvd-cve-mcp-server"]
    }
  }
}

Global Installation

npm install -g nvd-cve-mcp-server

Local Installation

npm install nvd-cve-mcp-server

๐Ÿš€ Usage

1. Configure as MCP Server

Configure in Claude Desktop or other MCP-compatible applications:

macOS/Linux (~/Library/Application Support/Claude/claude_desktop_config.json):

{
  "mcpServers": {
    "nvd-cve": {
      "command": "npx",
      "args": ["-y", "nvd-cve-mcp-server"]
    }
  }
}

Windows (%APPDATA%\Claude\claude_desktop_config.json):

{
  "mcpServers": {
    "nvd-cve": {
      "command": "npx",
      "args": ["-y", "nvd-cve-mcp-server"]
    }
  }
}

2. Direct Execution

npm start

๐Ÿ› ๏ธ Available Tools

1. get_cve_details

Retrieve detailed information for a specific CVE.

Parameters:

  • cve_id (required): CVE ID in format CVE-YYYY-NNNNN

Example:

Get details for CVE-2025-13583

Output Format:

# CVE-2025-13583

## ๐Ÿ“Š Basic Information

- **CVE ID**: CVE-2025-13583
- **CVSS Score**: 9.8
- **Severity**: CRITICAL
- **Published**: 2025-11-23
- **Last Modified**: 2025-11-26
- **CWE Type**: CWE-89

## ๐Ÿ“ Description

[Detailed vulnerability description]

## ๐Ÿ”— References

1. [VulDB](https://vuldb.com/?id.333344)
2. [GitHub Issue](https://github.com/rassec2/dbcve/issues/6)

## ๐ŸŒ Official Links

- [NVD Details](https://nvd.nist.gov/vuln/detail/CVE-2025-13583)
- [CVE Record](https://cve.org/CVERecord?id=CVE-2025-13583)

2. search_cves

Search for CVE vulnerabilities by keyword.

Parameters:

  • keyword (required): Search keyword

  • limit (optional): Number of results to return (default: 10, max: 20)

Example:

Search for CVEs related to "SQL injection"
Search for "WordPress" vulnerabilities, limit to 5 results

Output Format:

# CVE Search Results: "SQL injection"

Found 10 related vulnerabilities

| CVE ID | Severity | CVSS | Published | Description |
|--------|----------|------|-----------|-------------|
| CVE-2025-13583 | CRITICAL | 9.8 | 2025-11-23 | A vulnerability has been found in code-projects... |
| CVE-2025-13582 | HIGH | 7.3 | 2025-11-23 | A vulnerability was found in code-projects... |

๐Ÿ“‹ Usage Examples

Using with Claude

  1. Query Specific CVE:

    Please help me query CVE-2025-13583 details
  2. Search Vulnerabilities:

    Search for recent SQL injection vulnerabilities
  3. Search by Product:

    Find WordPress-related CVE vulnerabilities

๐Ÿ”ง Technical Architecture

Data Sources

  1. NVD API (Primary)

    • Official REST API: https://services.nvd.nist.gov/rest/json/cves/2.0

    • Provides structured JSON data

    • Includes complete CVSS scores, CWE classifications, etc.

  2. NVD Web (Fallback)

    • Web scraping when API is unavailable

    • Uses Cheerio for HTML parsing

    • Extracts key vulnerability information

Core Dependencies

  • @modelcontextprotocol/sdk: MCP protocol implementation

  • axios: HTTP client

  • cheerio: HTML parser

๐Ÿ“Š Data Format

CVE Details Object

{
  id: "CVE-2025-13583",
  description: "Vulnerability description...",
  cvssScore: 9.8,
  severity: "CRITICAL",
  published: "2025-11-23T10:15:03.000",
  lastModified: "2025-11-26T12:39:31.000",
  references: [
    {
      url: "https://example.com",
      source: "VulDB"
    }
  ],
  cweId: "CWE-89",
  source: "api" // or "web"
}

โš ๏ธ Important Notes

  1. API Rate Limits: NVD API has rate limits, please use responsibly

  2. Network Requirements: Requires access to nvd.nist.gov

  3. Data Freshness: CVE information is updated regularly, check for latest data

  4. Format Validation: CVE ID must follow CVE-YYYY-NNNNN format

๐Ÿ› Troubleshooting

Common Issues

  1. API Timeout

    • Check network connection

    • System will automatically switch to web scraping mode

  2. CVE Not Found

    • Verify CVE ID format is correct

    • Check if CVE has been published to NVD

  3. No Search Results

    • Try using more general keywords

    • Check spelling

๐Ÿ“ Development

Project Structure

nvd-cve-mcp-server/
โ”œโ”€โ”€ src/
โ”‚   โ””โ”€โ”€ index.js          # Main server code
โ”œโ”€โ”€ package.json          # Project configuration
โ””โ”€โ”€ README.md            # Documentation

Local Development

# Development mode (auto-restart)
npm run dev

# Production mode
npm start

๐Ÿค Contributing

Issues and Pull Requests are welcome!

๐Ÿ“„ License

MIT License

๐Ÿ‘ฅ Author

SOCTeam.AI


Note: This tool is for security research and educational purposes only. Please comply with relevant laws, regulations, and ethical standards.

Available Tools

2 tools
get_cve_detailsA

ๆ นๆฎCVE ID่Žทๅ–่ฏฆ็ป†็š„ๆผๆดžไฟกๆฏ,ๅŒ…ๆ‹ฌๆ่ฟฐใ€CVSS่ฏ„ๅˆ†ใ€ไธฅ้‡็จ‹ๅบฆใ€ๅ‚่€ƒ้“พๆŽฅ็ญ‰

ParametersJSON Schema
NameRequiredDescriptionDefault
cve_idYesCVE ID (ไพ‹ๅฆ‚: CVE-2025-13583)

TDQS

A3.8/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description must fully disclose behavior. It mentions the tool retrieves details but does not confirm it is a read-only operation, specify any authentication needs, rate limits, or describe the response structure. This is insufficient for a tool with no annotation safety net.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single, front-loaded sentence that conveys the essential purpose and return content without any unnecessary words. It is highly efficient for a simple tool.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool's simplicity (one required parameter, no output schema), the description covers the core functionality and expected results. However, it lacks usage guidance and behavioral details, which slightly limits completeness for an agent unfamiliar with the context.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema covers the single parameter 'cve_id' with a regex pattern and description. The tool description adds semantic value by listing the types of details returned (description, CVSS score, severity, reference links), which enriches the agent's understanding of the output beyond the schema alone.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool retrieves detailed vulnerability information by CVE ID, including description, CVSS score, severity, and reference links. This specific verb-resource combination ('get' + 'cve_details') and the explicit listing of return fields distinguish it from the sibling 'search_cves' tool.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies usage via the input requirement ('ๆ นๆฎCVE ID'), but does not explicitly state when to use this tool versus the sibling 'search_cves', nor does it provide any exclusions or prerequisites. Guidance is only implied.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

search_cvesA

ๆ นๆฎๅ…ณ้”ฎๅญ—ๆœ็ดขCVEๆผๆดž,ๆ”ฏๆŒๆœ็ดขๆผๆดžๆ่ฟฐใ€ไบงๅ“ๅ็งฐใ€ไพ›ๅบ”ๅ•†็ญ‰

ParametersJSON Schema
NameRequiredDescriptionDefault
keywordYesๆœ็ดขๅ…ณ้”ฎๅญ— (ไพ‹ๅฆ‚: SQL injection, WordPress, Apache)
limitNo่ฟ”ๅ›ž็ป“ๆžœๆ•ฐ้‡้™ๅˆถ (้ป˜่ฎค: 10, ๆœ€ๅคง: 20)

TDQS

A3.9/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the burden. It discloses that the search covers multiple fields, but lacks details on behavior like result ordering, matching logic, rate limits, or handling of empty results.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single sentence that efficiently captures the tool's purpose and scope. It is front-loaded and concise, though slightly more structure could improve readability.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool has only two parameters and no output schema, the description adequately covers the key aspects. It explains what the tool does and what it searches, but lacks details on return format or behavior.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, and the description adds value by specifying which fields (description, product name, vendor) are searched, which is not evident from the parameter definitions alone.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool searches CVE vulnerabilities by keyword and specifies the fields it supports (description, product name, vendor). It distinguishes from the sibling tool get_cve_details, which provides details for a specific CVE.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies usage for broad searches but does not explicitly state when to use it versus the sibling tool or provide alternative scenarios. No exclusions or conditions are mentioned.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 2 tool updatesv1.0.2
    • First observedget_cve_details
    • First observedsearch_cves

TDQS

A3.9/5.0

Scored across 2 tools

Disambiguation5/5

Each tool has a clearly distinct purpose: one retrieves details by specific CVE ID, the other searches by keywords. No overlap or ambiguity.

Naming Consistency5/5

Both tools follow a consistent verb_noun pattern (get_cve_details, search_cves), making them predictable and easy to understand.

Tool Count3/5

With only 2 tools, the set is minimal but covers basic discovery and retrieval. For a narrow CVE lookup server, it is justifiable, but feels thin for broader use.

Completeness2/5

Missing essential operations like listing recent CVEs or filtering by severity/date. Search covers some discovery but lacks a way to browse all entries, creating notable gaps.

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    D
    maintenance
    Provides live CVE data from NVD and EPSS without API key, enabling AI assistants to look up CVSS scores, search vulnerabilities, and check product CVEs.
    3
    MIT
  • F
    license
    Not graded
    quality
    D
    maintenance
    Enables CVE vulnerability lookup and search using the National Vulnerability Database (NVD), allowing users to retrieve detailed information about specific CVEs and search for vulnerabilities by keyword.
    -