Back to Browse

Osv Dev MCP Server

Developer ToolsLow Risk10.0MCP RegistryRemote
Free

Server data from the Official MCP Registry

OSV.dev — Google's open-source vulnerability database

About

OSV.dev — Google's open-source vulnerability database

Remote endpoints: streamable-http: https://gateway.pipeworx.io/osv-dev/mcp

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (1 strong, 0 medium validity signals). No known CVEs in dependencies. Imported from the Official MCP Registry. Trust signals: trusted author (400/401 approved). 1 finding(s) downgraded by scanner intelligence.

14 tools verified · Open access · 1 issue found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

How to Connect

Remote Plugin

No local installation needed. Your AI client connects to the remote endpoint directly.

Add this to your MCP configuration to connect:

{
  "mcpServers": {
    "io-github-pipeworx-io-osv-dev": {
      "url": "https://gateway.pipeworx.io/osv-dev/mcp"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

mcp-osv-dev

OSV.dev MCP — Google's open-source vulnerability database.

Part of Pipeworx — an MCP gateway connecting AI agents to 673+ live data sources.

Tools

ToolDescription
vulnerabilitiesQuery vulnerabilities by package (+ optional version) or git commit.
query_batchBatch query (≤1000 queries). Pass an array of {package: {name, ecosystem}, version?} or {commit}.
getFull vulnerability record by id (CVE-…, GHSA-…, OSV-…).

Quick Start

Add to your MCP client (Claude Desktop, Cursor, Windsurf, etc.):

{
  "mcpServers": {
    "osv-dev": {
      "url": "https://gateway.pipeworx.io/osv-dev/mcp"
    }
  }
}

Or connect to the full Pipeworx gateway for access to all 673+ data sources:

{
  "mcpServers": {
    "pipeworx": {
      "url": "https://gateway.pipeworx.io/mcp"
    }
  }
}

Using with ask_pipeworx

Instead of calling tools directly, you can ask questions in plain English:

ask_pipeworx({ question: "your question about Osv Dev data" })

The gateway picks the right tool and fills the arguments automatically.

More

License

MIT

Reviews

No reviews yet

Be the first to review this server!

Osv Dev MCP Server - OSV.dev — Google's open-source vulnerability database | MCP Marketplace