Back to Browse

Cve Cache MCP Server

Developer ToolsLow Risk10.0MCP RegistryLocal
Free

Server data from the Official MCP Registry

Recent CVE + GHSA cache for AI agents auditing dependencies (npm/PyPI/Cargo/Maven/Go).

About

Recent CVE + GHSA cache for AI agents auditing dependencies (npm/PyPI/Cargo/Maven/Go).

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (2 strong, 4 medium validity signals). No known CVEs in dependencies. Package registry verified. Imported from the Official MCP Registry.

3 files analyzed · 1 issue found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

file_system

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

Override remote snapshot URLOptional

Environment variable: CVE_CACHE_URL

Skip remote fetchOptional

Environment variable: CVE_CACHE_LOCAL_ONLY

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-weiseer-cve-cache": {
      "env": {
        "CVE_CACHE_URL": "your-cve-cache-url-here",
        "CVE_CACHE_LOCAL_ONLY": "your-cve-cache-local-only-here"
      },
      "args": [
        "-y",
        "@weiseer/cve-cache-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

@weiseer/cve-cache-mcp

Recent CVE + GHSA cache as a stdio MCP server.

Probe P-005 by weiseer.

What it does

Cached, structured snapshot of recent CVE + GitHub Security Advisory records — for AI agents auditing dependencies or screening new packages.

Your agent can:

  • lookup_cve — full record for one CVE/GHSA ID
  • find_for_package — all CVEs affecting a package by ecosystem (npm/PyPI/Cargo/Maven/Go)
  • list_recent_critical — recent high-severity CVEs (default: 7-day, CVSS ≥ 7)
  • severity_summary — counts by severity bucket

Why use this instead of your agent querying NVD itself

Agent DIYcve-cache
Source queryNVD JSON feeds + GHSA GraphQL1 MCP call
Token cost (NVD records are large)$0.05-0.20$0 free / $0.00005 paid
Latency2-10 seconds<100ms
Cross-ecosystem normalizationPer-source schemaPre-normalized

Install

npm install -g @weiseer/cve-cache-mcp

Use with Claude Desktop / Cursor / Cline / Continue / Windsurf

{
  "mcpServers": {
    "cve-cache": {
      "command": "npx",
      "args": ["-y", "@weiseer/cve-cache-mcp"]
    }
  }
}

License

Apache-2.0. Catalog data: derived from public CVE/NVD/GHSA feeds (CC0/public domain).

Reviews

No reviews yet

Be the first to review this server!