OSV-MCP
OSV MCP server implementation
Documentation
MCP Server For OSV
A lightweight MCP (Model Context Protocol) server for OSV Database API.
Example:
Tools Provided
Overview
| name | description |
|---|---|
| query_package_cve | List all the CVE IDs for a specific package. Specific version can be passed as well for more narrow scope CVE IDs. |
| query_for_cve_affected | Query the OSV database for a CVE and return all affected versions of the package. |
| query_for_cve_fix_versions | Query the OSV database for a CVE and return all versions that fix the vulnerability. |
| get_ecosystems | Query the MCP for current supported ecosystems. |
Detailed Description
- query_package_cve
- Query the OSV database for a package and return the CVE IDs.
- Input parameters:
- `package` (string, required): The package name to query
- `version` (string, optional): The version of the package to query. If not specified, queries all versions
- `ecosystem` (string, optional): The ecosystem of the package. Defaults to "PyPI" for Python packages
- Returns a list of CVE IDs with their details
- query_for_cve_affected
- Query the OSV database for a CVE and return all affected versions.
- Input parameters:
- `cve` (string, required): The CVE ID to query (e.g., "CVE-2018-1000805")
- Returns a list of affected version strings
- query_for_cve_fix_versions
- Query the OSV database for a CVE and return all versions that fix the vulnerability.
- Input parameters:
- `cve` (string, required): The CVE ID to query (e.g., "CVE-2018-1000805")
- Returns a list of fixed version strings
- get_ecosystems
- Query for all current supported ecosystems by the MCP servers.
- Return a dict with the key being the ecosystem name and the value the programming language / OS.
Prerequisites
1. Python 3.11 or higher: This project requires Python 3.11 or newer.
# Check your Python version
python --version2. Install uv: A fast Python package installer and resolver.
pip install uvOr use Homebrew:
brew install uvTested on
- [X] Cursor
- [X] Claude
Installation
1. Via Smithery:
npx -y @smithery/cli install @EdenYavin/OSV-MCP --client claude2. Locally:
1. Clone the repo: ```https://github.com/EdenYavin/OSV-MCP.git```
2. Configure your MCP Host (Cusrsor / Claude Desktop etc.):
{
"mcpServers": {
"osv-mcp": {
"command": "uv",
"args": ["--directory", "path-to/OSV-MCP", "run", "osv-server"],
"env": {}
}
}
}**Leave a review on VibeApp
if you enjoyed it :)!**
Frequently asked questions
What is OSV-MCP?
OSV-MCP is OSV MCP server implementation
How do I install OSV-MCP?
Open the GitHub repository and follow its README. Most MCP servers are added to your client's MCP config, then called by your agent.
Is OSV-MCP open source?
Yes — it is hosted on GitHub at https://github.com/EdenYavin/OSV-MCP and has 2 stars.
Related MCP tools
Cognee is the open-source AI memory platform for agents. Give your AI agents persistent long-term memory across sessions with a self-hosted knowledge graph engine.
Automate browser based workflows with AI
Hindsight: Agent Memory That Learns
A privacy-first app that strips AI watermarks from content you own.
Agent framework and applications built upon Qwen>=3.0, featuring Function Calling, MCP, Code Interpreter, RAG, Chrome extension, etc.
The power of Claude Code / GeminiCLI / CodexCLI + [Gemini / OpenAI / OpenRouter / Azure / Grok / Ollama / Custom Model / All Of The Above] working as one.
Run your own MCP server? See who uses it and what to fix.
Measure it with TrackMCP