Skip to content
OSINT Tradecraft
OSINT Tradecraft
Investigation skills · Vol. 8
← MCP catalog#019 · OSINT — Technical Infrastructure

CVE MCP Server

27 tools across 21 security APIs

Comprehensive vulnerability intelligence MCP covering CVE lookup, EPSS exploit prediction, CISA KEV catalog, MITRE ATT&CK, CWE, OSV.dev, and more. 8 of 27 tools require zero API keys.

Cost
Free · no API key
API key
Some integrations
Slug
cve-mcp
MCP.md
---
name: cve-mcp
category: osint-technical-infrastructure
cost: free
api_key_required: partial
repo: https://github.com/mukul975/cve-mcp-server
paired_skills: ["ip-and-asn-attribution", "github-and-source-leak-search", "cloud-bucket-discovery"]
capabilities: ["cve-lookup", "vulnerability-intel", "threat-intel"]
---

# CVE MCP Server — 27 tools across 21 security APIs

Comprehensive vulnerability intelligence MCP covering CVE lookup, EPSS exploit prediction, CISA KEV catalog, MITRE ATT&CK, CWE, OSV.dev, and more. 8 of 27 tools require zero API keys.

## Install

```
uvx cve-mcp-server
```

## Configuration

```json
{
  "mcpServers": {
    "cve": {
      "command": "uvx",
      "args": ["cve-mcp-server"],
      "env": {
        "SHODAN_API_KEY": "YOUR_SHODAN_KEY_HERE",
        "VIRUSTOTAL_API_KEY": "YOUR_VT_KEY_HERE"
      }
    }
  }
}
```

Omit the env keys if you don't have Shodan or VirusTotal accounts — 8 tools still work without them.

## What it adds

Claude triages and prioritizes vulnerability findings mid-investigation — looking up a CVE's EPSS score to predict exploitation likelihood, checking CISA KEV to see if it's actively exploited in the wild, mapping to MITRE ATT&CK technique IDs, and pulling exploit references. Useful for scope-defining recon write-ups and for contextualizing Shodan/Censys findings.

## Pairs with skills

- 042 `ip-and-asn-attribution`
- 046 `github-and-source-leak-search`
- 047 `cloud-bucket-discovery`

## Cost

8 of 27 tools free with no keys (EPSS, CISA KEV, OSV.dev, MITRE ATT&CK, CWE, NVD limited). Shodan and VirusTotal keys extend coverage.
Pairs with skills
  • #042ip-and-asn-attribution
  • #046github-and-source-leak-search
  • #047cloud-bucket-discovery

This MCP gives your agent the tools to execute the workflow described by these skills — instead of just describing it.

Bundled in the Toolkit

This MCP is one of 36 pre-configured servers in the Investigator's MCP Toolkit. One-command installer, $149 one-time.

Pricing
Back to MCP catalog
CVE MCP Server — 27 tools across 21 security APIs — MCP server · OSINT Tradecraft