Search and audit NIST NVD CVEs by keyword, severity, CWE, CISA KEV status, and CPE.
Search and audit CVEs by keyword, severity, CWE, CISA KEV status, and CPE via the NIST National Vulnerability Database. STDIO or Streamable HTTP.
Public Hosted Server: https://nist-nvd.caseyjhand.com/mcp
CVE and CPE data from the NIST National Vulnerability Database. Search and audit vulnerabilities by keyword, severity, CWE, or CISA KEV status, resolve products to CPE names, and track a CVE's revision history from any MCP client. Runs as a stdio process, a local Streamable HTTP server, or the public hosted endpoint above.
| Tool | Description |
|---|---|
nvd_search_cves | Search CVEs by keyword, severity, CWE, date range, or CISA KEV status. |
nvd_get_cve | Fetch one or more CVEs by ID — full CVSS scores, CWE, CPE configs, KEV fields, and references. |
nvd_search_cpes | Search the NVD CPE dictionary by product keyword or partial match string. |
nvd_audit_cpe | Find all CVEs affecting a specific product version by CPE name or virtual match string. |
nvd_get_cve_history | Retrieve the change history for a CVE — score revisions, status transitions, and reference additions. |
| Resource | Description |
|---|---|
nvd://cve/{cveId} | Full CVE record by ID — same data as nvd_get_cve for a single ID, as a stable URI for injectable context. |
All resource data is also reachable via tools.
nvd_search_cves toolexactPhrase: true for an exact-phrase match — requires keywordseverityVersion: "v3" or "v4"), CWE ID, CISA KEV status, noRejected (default true)pubDays/lastModDays convenience shorthands (auto-clamped to 120 days, clamping reported in the enrichment) or explicit ISO 8601 ranges (120-day max span, both ends required); the two forms per axis are mutually exclusivelimit (up to 2000, default 20) and offsetnvd_get_cve for full detailnvd_get_cve toolbrief: true returns trimmed rows (ID, status, top severity, KEV name, truncated description) — recommended for batches over 10includeReferences: false strips the references array; allLanguages: true renders every localized description instead of English-onlymissingIds enrichment field lists any requested IDs NVD didn't return… N more trailernvd_search_cpes tool"apache http server") or a partial CPEv2.3 pattern via cpeMatchString — at least one requiredlimit (up to 10,000, default 20) and offset — a vendor-level keyword can match tens of thousands of entries, so page rather than narrowing furthernvd_audit_cpe to resolve the exact CPE name a product needsnvd_audit_cpe toolcpeName (NVD auto-applies isVulnerable) or virtualMatchString with optional versionStart/versionEnd bounds (inclusive/exclusive)severityMin filter drops low-signal entries from the fetched page — it can only remove what limit already retrievedlimit (up to 2000, default 20) and offset — page at a modest limit rather than raising it, since each result is a full recordauditTarget enrichment field echoes the CPE identifier used, so callers can verify the correct product was queriednvd_get_cve_history toolorder picks the anchor end — newest (default) reads most-recent-first, oldest reads NVD's native orderlimit (up to 2000, default 20) and offset, counted from the end order anchors toNVD_API_KEY and raise NVD_REQUEST_TIMEOUT_MSnvd://cve/{cveId} resourceapplication/json — same data as nvd_get_cve for one ID, with references and English-only descriptionscveId must match CVE-YYYY-NNNNN; a well-formed but unknown ID throws cve_not_foundBuilt on @cyanheads/mcp-ts-core: stdio and Streamable HTTP transports, pluggable auth (none / jwt / oauth), swappable storage (in-memory, filesystem, Supabase, Cloudflare KV/R2/D1), structured logging with optional OpenTelemetry tracing.
NVD-specific:
Retry-After holds the whole queue until NVD's window resets; keyless, a 403 fails fast and names NVD_API_KEY rather than spending the 5-request budget on retries that cannot outlast a 30-second windowmessage header, so a refused key surfaces as a config fault naming NVD_API_KEY rather than as a malformed CVE IDAgent-friendly output:
enrichment block on every response, carried on both structuredContent and the rendered text — total results, returned count, page offset, the filters actually applied, and any date-clamping events, so agents can reason about what was really queriedmissingIds in batch CVE lookups — a per-ID parity check instead of a silent partial resultcpeName or virtualMatchString reflected back so callers can verify the correct product was auditedA public instance is available at https://nist-nvd.caseyjhand.com/mcp — no installation required. Point any MCP client at it via Streamable HTTP:
{
"mcpServers": {
"nist-nvd-mcp-server": {
"type": "streamable-http",
"url": "https://nist-nvd.caseyjhand.com/mcp"
}
}
}
Add the following to your MCP client configuration file.
{
"mcpServers": {
"nist-nvd-mcp-server": {
"type": "stdio",
"command": "bunx",
"args": ["@cyanheads/nist-nvd-mcp-server@latest"],
"env": {
"MCP_TRANSPORT_TYPE": "stdio",
"MCP_LOG_LEVEL": "info",
"NVD_API_KEY": "your-api-key"
}
}
}
}
Or with npx (no Bun required):
{
"mcpServers": {
"nist-nvd-mcp-server": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@cyanheads/nist-nvd-mcp-server@latest"],
"env": {
"MCP_TRANSPORT_TYPE": "stdio",
"MCP_LOG_LEVEL": "info",
"NVD_API_KEY": "your-api-key"
}
}
}
}
Or with Docker:
{
"mcpServers": {
"nist-nvd-mcp-server": {
"type": "stdio",
"command": "docker",
"args": [
"run", "-i", "--rm",
"-e", "MCP_TRANSPORT_TYPE=stdio",
"-e", "NVD_API_KEY=your-api-key",
"ghcr.io/cyanheads/nist-nvd-mcp-server:latest"
]
}
}
}
For Streamable HTTP, set the transport and start the server:
MCP_TRANSPORT_TYPE=http MCP_HTTP_PORT=3010 NVD_API_KEY=... bun run start:http
# Server listens at http://localhost:3010/mcp
git clone https://github.com/cyanheads/nist-nvd-mcp-server.git
cd nist-nvd-mcp-server
bun install
cp .env.example .env
# edit .env and set NVD_API_KEY if you have one
| Variable | Description | Default |
|---|---|---|
NVD_API_KEY | NVD API key. Without it, rate limit is 5 req/30s; with it, 50 req/30s. Get one free at nvd.nist.gov/developers/request-an-api-key. | — |
NVD_REQUEST_TIMEOUT_MS | Per-request timeout in milliseconds. The history endpoint is slow without an API key — raise to 60000 if using nvd_get_cve_history without a key. | 10000 |
MCP_TRANSPORT_TYPE | Transport: stdio or http. | stdio |
MCP_HTTP_PORT | Port for HTTP server. | 3010 |
MCP_AUTH_MODE | Auth mode: none, jwt, or oauth. | none |
MCP_LOG_LEVEL | Log level (RFC 5424). | info |
LOGS_DIR | Directory for log files (Node.js only). | <project-root>/logs |
OTEL_ENABLED | Enable OpenTelemetry instrumentation. | false |
See .env.example for the full list of optional overrides.
Build and run:
# One-time build
bun run rebuild
# Run the built server
bun run start:stdio
# or
bun run start:http
Run checks and tests:
bun run devcheck # Lint, format, typecheck, security
bun run test # Vitest test suite
bun run lint:mcp # Validate MCP definitions against spec
docker build -t nist-nvd-mcp-server .
docker run --rm -e NVD_API_KEY=your-key -p 3010:3010 nist-nvd-mcp-server
The Dockerfile defaults to HTTP transport, stateless session mode, and logs to /var/log/nist-nvd-mcp-server. OpenTelemetry peer dependencies are installed by default — build with --build-arg OTEL_ENABLED=false to omit them.
| Directory | Purpose |
|---|---|
src/index.ts | createApp() entry point — registers tools/resources and inits services. |
src/config | Server-specific environment variable parsing and validation with Zod. |
src/mcp-server/tools | Tool definitions (*.tool.ts). |
src/mcp-server/resources | Resource definitions (*.resource.ts). |
src/services/nvd-http | NVD HTTP client with rate-limit pacing and retry. |
src/services/nvd-cve | CVE service — search, fetch-by-ID, CPE audit, change history, normalization. |
src/services/nvd-cpe | CPE service — dictionary search and normalization. |
src/services/nvd-source | Source service — resolves NVD contributor identifiers to their published names. |
tests/ | Unit and integration tests mirroring src/. |
See CLAUDE.md for development guidelines and architectural rules. The short version:
try/catch in tool logicctx.log for request-scoped logging, ctx.state for tenant-scoped storagesrc/mcp-server/*/definitions/index.tsIssues are welcome. Run checks and tests before submitting:
bun run devcheck
bun run test
Apache-2.0 — see LICENSE for details.
Source-derived launch command. Check the maintainer’s required arguments and credentials before running:
npx -y @cyanheads/nist-nvd-mcp-serverMerge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.
{
"mcpServers": {
"io-github-cyanheads-nist-nvd-mcp-server": {
"command": "npx",
"args": [
"-y",
"@cyanheads/nist-nvd-mcp-server"
]
}
}
}Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.
Claude Desktop setup referenceio.github.cyanheads/nist-nvd-mcp-server works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.