osv-mcp
An MCP server providing access to the OSV database for querying vulnerability information.
The OSV MCP Server is an SSE-based Model Context Protocol server that allows applications powered by LLMs to query the Open Source Vulnerabilities (OSV) database. It provides functionalities for querying vulnerabilities related to specific package versions or commits, batch querying for multiple packages or commits, and retrieving detailed information about specific vulnerabilities by their ID. The server is designed to be easily deployable and configurable, supporting secure, containerized deployment through ToolHive. It is built using Go and can be configured using environment variables for flexibility in deployment.
Features
- Query vulnerabilities for specific package versions or commits.
- Batch query vulnerabilities for multiple packages or commits.
- Retrieve detailed information about specific vulnerabilities by ID.
- Secure, containerized deployment using ToolHive.
- Configurable server settings via environment variables.
Tools
query_vulnerability
Query for vulnerabilities affecting a specific package version or commit.
query_vulnerabilities_batch
Query for vulnerabilities affecting multiple packages or commits at once.
get_vulnerability
Get details for a specific vulnerability by ID.