Favicon of cve-mcp-server

cve-mcp-server

MCP ServerSecurityPythonOpen source

cve-mcp-server is a Python MCP server for Claude Desktop with npx, uvx/pip, docker. Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan, VirusTotal, and more.

Decision snapshot

Is this a fit?

Best for

Connecting agents to external tools and data, Integrations workflows, Coding workflows, Data workflows

Works with

Claude Desktop, Python, Docker

Access

API key required authentication

Setup

npx, uvx/pip, docker, git clone

Project health

4 months ago · Apache-2.0 license

Considerations

Requires Python. Requires Docker. Requires Apache-2.0 license.

How to use cve-mcp-server

Install or run

pip install -e ".[test]"

Client configuration

{
  "mcpServers": {
    "cve-mcp": {
      "command": "python",
      "args": ["-m", "cve_mcp.server"],
      "cwd": "/absolute/path/to/cve-mcp-server",
      "env": {
        "NVD_API_KEY": "your-key-here",
        "GITHUB_TOKEN": "ghp_xxxxxxxxxxxxxxxxxxxx",
        "ABUSEIPDB_KEY": "your-abuseipdb-key",
        "GREYNOISE_API_KEY": "your-greynoise-key",
        "SHODAN_KEY": "your-shodan-key"
      }
    }
  }
}

Compatible clients

Claude Desktop

What is cve-mcp-server?

cve-mcp-server is a Python MCP server for Claude Desktop with npx, uvx/pip, docker. Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan, VirusTotal, and more. This profile combines repository metadata with install, compatibility, and usage signals so developers can quickly decide whether it fits their agent workflow before opening the source repository.

Trust signal
80/100
Maintenance signal
75/100
Adoption signal
68/100

Automated repository signals based on public metadata such as recency, license, installation evidence, and adoption. These are not a security audit or endorsement. See how SkillIndex evaluates profiles.

Key capabilities

  • Tool access support
  • Shell commands support
  • Browser use support
  • Spreadsheet work support
  • Anthropic provider support
  • Google provider support
  • pyproject.toml config support

Compatibility and setup

Install or run cve-mcp-server using npx. Check mukul975/cve-mcp-server for the latest setup command.

npxuvx/pipdockergit cloneremote URLClaude DesktopstdioHTTPSSE
  • Built for Python
  • Built for Docker
  • Install or run with npx
  • Install or run with uvx/pip
  • Install or run with docker
  • Install or run with git clone
  • Install or run with remote URL
  • Works with Claude Desktop

MCP metadata is retained with field-level source and confidence evidence. Undetected values remain unknown.

Requirements and access

PythonDockerApache-2.0 licenseAPI key requiredDatabase accessAPI key requiredDatabase accessNetwork access

Security and permissions

Review permissions before connecting any MCP server to an agent. Pay special attention to whether it can read local files, write data, call external services, or perform destructive actions.

API key required authenticationHosted or remote

When to use cve-mcp-server

  • Use it for connecting agents to external tools and data.
  • Use it for integrations workflows.
  • Use it for coding workflows.
  • Use it for data workflows.
  • Use it for claude desktop users.

Built with

PythonDockernpxuvx/pipdockergit cloneremote URLClaude DesktopstdioHTTPSSE

Verified compatibility and discovery

Frequently asked questions

What is cve-mcp-server?

cve-mcp-server is a Python MCP server for Claude Desktop with npx, uvx/pip, docker. Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan, VirusTotal, and more.

Who is cve-mcp-server best for?

cve-mcp-server is best for connecting agents to external tools and data, integrations workflows, coding workflows, data workflows, claude desktop users.

How do I install cve-mcp-server?

Install or run cve-mcp-server using npx. Check cve-mcp-server for the latest setup command.

Is cve-mcp-server actively maintained?

cve-mcp-server may need a closer maintenance check before production use.

Share:

Stars
567
Forks
94
Last commit
4 months ago
Last verified
Not yet verified
Metadata fetched
Jul 25, 2026
Repository age
5 months
License
Apache-2.0

Project health auto-fetched from the source repository.

Maintain this resource?

Review this source-backed profile, send a correction with evidence, or link to it from your documentation. Claims verify your relationship to the project; profile facts still require source evidence and editorial review.

Alternatives to cve-mcp-server