MCP Server For OSV

by BIGdeadLock

2 stars
28 downloads
Not rated
GitHub

About

MCP Server For OSV is a lightweight MCP server that provides access to the OSV Database API, enabling querying of package vulnerabilities, affected versions, and fix versions. It is intended for developers and security researchers using MCP-compatible hosts like Claude Desktop…

Details

Author
BIGdeadLock
GitHub stars
2
Downloads
28
Categories
Other

- List all CVE IDs for a package, optionally filtered by version and ecosystem.
- Query a CVE to retrieve all affected versions of a package.
- Query a CVE to retrieve all versions that fix the vulnerability.
- List currently supported ecosystems with their programming language or OS.

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name MCP Server For OSV
    Command (node, npx, python, etc.)

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

From the repository

Install via Smithery (npx -y @smithery/cli install @EdenYavin/OSV-MCP --client claude) or clone locally and configure your MCP host with the provided JSON config (using uv). The server offers four tools: query_package_cve, query_for_cve_affected, query_for_cve_fix_versions, and get_ecosystems.

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "mcp server for osv": {
            "OSV-MCP": {
                "command": "npx",
                "args": [
                    "-y",
                    "@smithery/cli",
                    "install",
                    "@EdenYavin/OSV-MCP",
                    "--client",
                    "claude"
                ]
            }
        }
    }
}

McpServers

{
    "OSV-MCP": {
        "command": "npx",
        "args": [
            "-y",
            "@smithery/cli",
            "install",
            "@EdenYavin/OSV-MCP",
            "--client",
            "claude"
        ]
    }
}

MCP Server For OSV

A lightweight MCP (Model Context Protocol) server for OSV Database API.

Example:

demo

---

Tools Provided

Overview

|name|description| |---|---| |query_package_cve|List all the CVE IDs for a specific package. Specific version can be passed as well for more narrow scope CVE IDs.| |query_for_cve_affected|Query the OSV database for a CVE and return all affected versions of the package.| |query_for_cve_fix_versions|Query the OSV database for a CVE and return all versions that fix the vulnerability.| |get_ecosystems|Query the MCP for current supported ecosystems.

Detailed Description

- query_package_cve
- Query the OSV database for a package and return the CVE IDs.
- Input parameters:
- package (string, required): The package name to query
- version (string, optional): The version of the package to query. If not specified, queries all versions
- ecosystem (string, optional): The ecosystem of the package. Defaults to "PyPI" for Python packages
- Returns a list of CVE IDs with their details

- query_for_cve_affected
- Query the OSV database for a CVE and return all affected versions.
- Input parameters:
- cve (string, required): The CVE ID to query (e.g., "CVE-2018-1000805")
- Returns a list of affected version strings

- query_for_cve_fix_versions
- Query the OSV database for a CVE and return all versions that fix the vulnerability.
- Input parameters:
- cve (string, required): The CVE ID to query (e.g., "CVE-2018-1000805")
- Returns a list of fixed version strings

- get_ecosystems
- Query for all current supported ecosystems by the MCP servers.
- Return a dict with the key being the ecosystem name and the value the programming language / OS.

---

Prerequisites

1. Python 3.11 or higher: This project requires Python 3.11 or newer.

   # Check your Python version
python --version

2. Install uv: A fast Python package installer and resolver.

   pip install uv

Or use Homebrew:
   brew install uv

---

Tested on

- [X] Cursor
- [X] Claude

---

Installation

1. Via Smithery:

npx -y @smithery/cli install @EdenYavin/OSV-MCP --client claude

2. Locally:

1. Clone the repo: ``https://github.com/EdenYavin/OSV-MCP.git

    2. Configure your MCP Host (Cusrsor / Claude Desktop etc.):

json
{
"mcpServers": {
"osv-mcp": {
"command": "uv",
"args": ["--directory", "path-to/OSV-MCP", "run", "osv-server"],
"env": {}
}
}
}

``

---

Leave a review on VibeApp
if you enjoyed it :)!

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.