MCP-Server

osv-advisory-mcp-server

io.github.cyanheads/osv-advisory-mcp-server
Entwicklertools Sicherheit Öffentlich und erreichbar MCP 2025-11-25

Was dieses MCP kann

Queries OSV.dev for package vulnerabilities and audits dependency lists across software ecosystems.

osv_get_vulnerability
Osv Get Vulnerability
Fetch the full advisory record for an OSV vulnerability ID. Returns the complete record: summary, full details text, CVE aliases, all affected packages and version ranges, fix versions, CVSS severity vectors, CWE weakness IDs, and references. Use when osv_query_package or osv_query_batch returns a vuln ID and you need the full advisory context — eligibility criteria, scope of affected packages, or remediation guidance.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['id'], 'properties': {'id': {'type': 'string', 'pattern': '^[A-Za-z][A-Za-z0-9_]*-\\S(.*\\S)?$', 'description': 'One exact, complete OSV advisory ID from any OSV source database, matched case-sensitively. Prefixes include "GHSA-" (GitHub), "PYSEC-" (PyPI), "RUSTSEC-" (Rust), "GO-" (Go), "DSA-"/"DLA-" (Debian), "USN-" (Ubuntu), "RHSA-" (Red Hat), and "CVE-". No wildcards or partial IDs â\x80\x94 take IDs from osv_query_package or osv_query_batch results. Example: "GHSA-29mw-wpgm-hmr9".'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'anyOf': [{'not': {'required': ['error']}, 'required': ['id', 'summary', 'details', 'aliases', 'published', 'modified', 'severity', 'severityLabel', 'severitySource', 'affected', 'cweIds', 'references', 'schemaVersion']}, {'required': ['error']}], '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'id': {'type': 'string', 'description': 'OSV vulnerability ID.'}, 'error': {'type': 'object', 'required': ['code', 'message'], 'properties': {'code': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'JSON-RPC error code for this failure.'}, 'data': {'type': 'object', 'properties': {'reason': {'type': 'string', 'examples': ['vulnerability_not_found'], 'description': 'Machine-readable failure mode. Declared by this tool: `vulnerability_not_found`: The requested OSV ID does not exist in the database. Other values are possible when a failure originates below the handler.'}, 'recovery': {'type': 'object', 'required': ['hint'], 'properties': {'hint': {'type': 'string'}}, 'description': 'Actionable next step for the caller.', 'additionalProperties': {}}, 'retryable': {'type': 'boolean', 'description': 'Whether retrying may succeed.'}}, 'additionalProperties': {}}, 'message': {'type': 'string', 'description': 'Human-readable description of what went wrong.'}}, 'description': 'Present when the call failed. Absent on success.', 'additionalProperties': {}}, 'cweIds': {'type': 'array', 'items': {'type': 'string', 'description': 'A CWE weakness ID.'}, 'description': 'CWE weakness classifications (e.g. ["CWE-79"]). Present on GitHub Advisory Database records; empty otherwise.'}, 'aliases': {'type': 'array', 'items': {'type': 'string', 'description': 'An alternative ID (usually a CVE ID).'}, 'description': 'Alternative IDs â\x80\x94 usually CVE IDs. Accepted by nvd_get_cve on nist-nvd-mcp-server for CVSS base score, EPSS exploitation probability, and CISA KEV status.'}, 'details': {'type': 'string', 'description': 'Full advisory text, typically in Markdown. May include proof-of-concept, reproduction steps, or remediation guidance.'}, 'summary': {'type': 'string', 'description': 'One-line advisory description.'}, 'affected': {'type': 'array', 'items': {'type': 'object', 'required': ['packageName', 'ecosystem', 'ranges'], 'properties': {'purl': {'type': 'string', 'description': 'Package URL (e.g. "pkg:npm/lodash").'}, 'ranges': {'type': 'array', 'items': {'type': 'object', 'required': ['rangeType'], 'properties': {'repo': {'type': 'string', 'description': 'Source repository URL for GIT ranges. Absent on version ranges.'}, 'fixed': {'type': 'string', 'description': 'The last "fixed" event of this range (convenience view â\x80\x94 a multi-interval range carries several; see events[]).'}, 'events': {'type': 'array', 'items': {'type': 'object', 'required': ['type', 'value'], 'properties': {'type': {'type': 'string', 'description': 'Event boundary type: "introduced", "fixed", "last_affected", or "limit".'}, 'value': {'type': 'string', 'description': 'Version string or commit identifier at this boundary.'}}, 'description': 'One ordered range event.', 'additionalProperties': False}, 'description': 'Ordered event boundaries defining the affected interval(s) â\x80\x94 the loss-free view preserving multiple introduced/fixed pairs the scalar fields collapse.'}, 'rangeType': {'type': 'string', 'description': '"SEMVER", "ECOSYSTEM", or "GIT".'}, 'introduced': {'type': 'string', 'description': 'First affected version (convenience view â\x80\x94 the last "introduced" event; see events[] for full interval order).'}, 'lastAffected': {'type': 'string', 'description': 'Last affected version when no fix exists (convenience view â\x80\x94 see events[]).'}}, 'description': 'One version range.', 'additionalProperties': False}, 'description': 'Version ranges affected.'}, 'severity': {'type': 'array', 'items': {'type': 'object', 'required': ['type', 'score'], 'properties': {'type': {'type': 'string', 'description': 'Severity type: "CVSS_V3", "CVSS_V4", "CVSS_V2", or "Ubuntu".'}, 'score': {'type': 'string', 'description': 'CVSS vector string, or the Ubuntu priority (e.g. "medium") for type "Ubuntu".'}}, 'description': 'One package-level severity entry.', 'additionalProperties': False}, 'description': 'Severity entries scoped to this package. Present only when the advisory scores packages separately; the record-level severity is then empty.'}, 'versions': {'type': 'array', 'items': {'type': 'string', 'description': 'An explicitly-listed affected version.'}, 'description': 'Explicit affected versions enumerated by the advisory. Absent or empty when affected versions are expressed only as ranges.'}, 'ecosystem': {'type': 'string', 'description': 'Affected package ecosystem. Empty for source-only advisories.'}, 'packageName': {'type': 'string', 'description': 'Affected package name. Empty for source-only advisories (GIT ranges with no package identity).'}}, 'description': 'One affected package entry.', 'additionalProperties': False}, 'description': 'All affected packages and their version ranges. An advisory may span multiple packages or ecosystems.'}, 'modified': {'type': 'string', 'description': 'ISO 8601 timestamp of last modification.'}, 'severity': {'type': 'array', 'items': {'type': 'object', 'required': ['type', 'score'], 'properties': {'type': {'type': 'string', 'description': 'Severity type: "CVSS_V3", "CVSS_V4", "CVSS_V2", or "Ubuntu".'}, 'score': {'type': 'string', 'description': 'CVSS vector string, or the Ubuntu priority (e.g. "medium") for type "Ubuntu".'}}, 'description': 'One record-level severity entry.', 'additionalProperties': False}, 'description': 'Record-level severity entries (CVSS vectors, Ubuntu priorities). Empty for unscored advisories and for advisories that score each affected package separately.'}, 'published': {'type': 'string', 'description': 'ISO 8601 timestamp when published.'}, 'withdrawn': {'type': 'string', 'description': 'ISO 8601 timestamp when this advisory was withdrawn. Present ONLY on withdrawn advisories â\x80\x94 a withdrawn record has been retracted and must not be treated as an active vulnerability.'}, 'references': {'type': 'array', 'items': {'type': 'object', 'required': ['type', 'url'], 'properties': {'url': {'type': 'string', 'description': 'URL of the reference.'}, 'type': {'type': 'string', 'description': 'Reference type: "ADVISORY", "WEB", "PACKAGE", "REPORT", "FIX", "GIT", etc.'}}, 'description': 'One reference entry.', 'additionalProperties': False}, 'description': 'Advisory references â\x80\x94 NVD links, patches, vendor advisories, PoC reports.'}, 'schemaVersion': {'type': 'string', 'description': 'OSV schema version this record conforms to (e.g. "1.7.3").'}, 'severityLabel': {'type': ['string', 'null'], 'description': 'Severity label ("LOW", "MODERATE", "HIGH", "CRITICAL") from the first source that yields one: database_specific.severity, an Ubuntu priority, then the highest CVSS v3/v4 score (0.1â\x80\x933.9 LOW, 4.0â\x80\x936.9 MODERATE, 7.0â\x80\x938.9 HIGH, 9.0â\x80\x9310.0 CRITICAL). Uses every affected package severity entry when the record-level list is empty. Null when no source yields a label.'}, 'severitySource': {'anyOf': [{'type': 'object', 'required': ['type', 'score'], 'properties': {'type': {'enum': ['database_specific', 'Ubuntu', 'CVSS_V3', 'CVSS_V4'], 'type': 'string', 'description': 'Source kind: the database_specific.severity label, an Ubuntu priority, or a CVSS vector.'}, 'score': {'type': 'string', 'description': 'The published value the label came from: the database_specific.severity text, the Ubuntu priority, or the CVSS vector.'}, 'computedScore': {'type': 'number', 'description': 'CVSS score computed from the vector as published: a CVSS 4.0 vector over every metric group it carries (threat and environmental included), a CVSS 3.x vector with its temporal metrics. Present only for CVSS sources.'}}, 'additionalProperties': False}, {'type': 'null'}], 'description': 'The severity entry severityLabel was derived from. Null exactly when the label is.'}}, 'additionalProperties': False}
osv_list_ecosystems
Osv List Ecosystems
Return the supported ecosystem identifier strings for osv_query_package and osv_query_batch: every ecosystem the OSV schema names that OSV.dev accepts at query time, plus GIT, as verified on 2026-09-24. Ecosystem strings are case-sensitive exact matches — passing "pypi" instead of "PyPI" returns an error from the API. Use this tool to discover valid ecosystem strings before querying, or to verify an ecosystem identifier from a lockfile format. The list is static and may lag ecosystems added after that date.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'anyOf': [{'not': {'required': ['error']}, 'required': ['ecosystems', 'note']}, {'required': ['error']}], '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'note': {'type': 'string', 'description': 'Advisory note about list currency and canonical source.'}, 'error': {'type': 'object', 'required': ['code', 'message'], 'properties': {'code': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'JSON-RPC error code for this failure.'}, 'data': {'type': 'object', 'properties': {'reason': {'type': 'string', 'description': 'Machine-readable failure mode.'}, 'recovery': {'type': 'object', 'required': ['hint'], 'properties': {'hint': {'type': 'string'}}, 'description': 'Actionable next step for the caller.', 'additionalProperties': {}}, 'retryable': {'type': 'boolean', 'description': 'Whether retrying may succeed.'}}, 'additionalProperties': {}}, 'message': {'type': 'string', 'description': 'Human-readable description of what went wrong.'}}, 'description': 'Present when the call failed. Absent on success.', 'additionalProperties': {}}, 'ecosystems': {'type': 'array', 'items': {'type': 'string', 'description': 'A supported ecosystem identifier string.'}, 'description': 'Supported ecosystem identifier strings. These are case-sensitive exact matches required by the ecosystem parameter of osv_query_package and osv_query_batch.'}}, 'additionalProperties': False}
osv_query_batch
Osv Query Batch
Query vulnerabilities for multiple packages in one call — the primary tool for dependency audits, SBOM scanning, and lockfile triage. Pass an array of {name, ecosystem, version} tuples (up to 1000). Each entry in the response corresponds positionally to the input. Each finding includes CVE aliases for chaining to nist-nvd-mcp-server for CVSS scoring.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['packages'], 'properties': {'packages': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'ecosystem', 'version'], 'properties': {'name': {'type': 'string', 'pattern': '\\S', 'description': 'Package name as it appears in the ecosystem.'}, 'version': {'type': 'string', 'pattern': '\\S', 'description': 'Exact version string to check.'}, 'ecosystem': {'type': 'string', 'pattern': '\\S', 'description': 'Ecosystem identifier. Case-sensitive exact match. Use osv_list_ecosystems to validate.'}}, 'description': 'One package to audit.'}, 'maxItems': 1000, 'minItems': 1, 'description': 'Packages to audit. One entry per dependency. Positional: result[i] corresponds to packages[i].'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'anyOf': [{'not': {'required': ['error']}, 'required': ['results', 'summary']}, {'required': ['error']}], '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'error': {'type': 'object', 'required': ['code', 'message'], 'properties': {'code': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'JSON-RPC error code for this failure.'}, 'data': {'type': 'object', 'properties': {'reason': {'type': 'string', 'description': 'Machine-readable failure mode.'}, 'recovery': {'type': 'object', 'required': ['hint'], 'properties': {'hint': {'type': 'string'}}, 'description': 'Actionable next step for the caller.', 'additionalProperties': {}}, 'retryable': {'type': 'boolean', 'description': 'Whether retrying may succeed.'}}, 'additionalProperties': {}}, 'message': {'type': 'string', 'description': 'Human-readable description of what went wrong.'}}, 'description': 'Present when the call failed. Absent on success.', 'additionalProperties': {}}, 'notice': {'type': 'string', 'description': 'Present on all-clean or all-errors batches â\x80\x94 the aggregate outcome for content-only clients.'}, 'results': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'ecosystem', 'version', 'vulnerable', 'truncated', 'error', 'vulnCount', 'vulns'], 'properties': {'name': {'type': 'string', 'description': 'Package name from input.'}, 'error': {'type': ['string', 'null'], 'description': 'Per-package error message (e.g. invalid ecosystem). Null on success.'}, 'vulns': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'summary', 'aliases', 'severityLabel', 'fixedVersions'], 'properties': {'id': {'type': 'string', 'description': 'OSV vulnerability ID.'}, 'aliases': {'type': 'array', 'items': {'type': 'string', 'description': 'A CVE ID or other alias.'}, 'description': 'CVE IDs and other aliases. Accepted by nist-nvd-mcp-server for CVSS/KEV/EPSS context.'}, 'summary': {'type': 'string', 'description': 'One-line advisory description.'}, 'fixedVersions': {'type': 'array', 'items': {'type': 'string', 'description': 'A version that fixes the vulnerability for this package.'}, 'description': "Every fixed version the advisory lists for this row's package, in record order â\x80\x94 one per affected interval, typically one per release line. Excludes other packages' fixes and GIT commits. Empty when the advisory lists no fix for this package."}, 'severityLabel': {'type': ['string', 'null'], 'description': 'Severity label: "LOW", "MODERATE", "HIGH", "CRITICAL", or null. Same derivation as osv_query_package: database_specific.severity, then an Ubuntu priority, then the highest CVSS v3/v4 score, using this row\'s package-level severity entries when the record has none.'}}, 'description': 'One vulnerability found for this package.', 'additionalProperties': False}, 'description': 'Vulnerabilities found. Empty array when clean.'}, 'version': {'type': 'string', 'description': 'Version from input.'}, 'ecosystem': {'type': 'string', 'description': 'Ecosystem from input.'}, 'truncated': {'type': 'boolean', 'description': 'True when OSV paginated beyond the fetch cap for this package â\x80\x94 its result may be INCOMPLETE. A truncated row with no vulnerabilities is NOT confirmed clean.'}, 'vulnCount': {'type': 'number', 'description': 'Number of vulnerabilities found. 0 when not vulnerable or on error.'}, 'vulnerable': {'type': 'boolean', 'description': 'True if any vulnerabilities were found.'}}, 'description': 'Result for one package.', 'additionalProperties': False}, 'description': 'Per-package results, positionally matching the input array.'}, 'summary': {'type': 'object', 'required': ['totalPackages', 'vulnerableCount', 'cleanCount', 'truncatedCount', 'errorCount', 'totalVulns', 'worstSeverity'], 'properties': {'cleanCount': {'type': 'number', 'description': 'Packages confirmed clean â\x80\x94 no vulnerabilities, no error, and not truncated.'}, 'errorCount': {'type': 'number', 'description': 'Packages that returned an error (e.g. invalid ecosystem).'}, 'totalVulns': {'type': 'number', 'description': 'Total vulnerability instances across all packages (may double-count shared advisories).'}, 'totalPackages': {'type': 'number', 'description': 'Total packages queried.'}, 'worstSeverity': {'type': ['string', 'null'], 'description': 'Highest severity label seen across all findings, or null if no severity data available.'}, 'truncatedCount': {'type': 'number', 'description': 'Packages whose OSV results were truncated (may be incomplete). A truncated package with no findings is NOT counted as clean.'}, 'vulnerableCount': {'type': 'number', 'description': 'Packages with at least one vulnerability.'}}, 'description': 'Aggregate statistics across the full batch.', 'additionalProperties': False}, 'effectiveQuery': {'type': 'string', 'description': 'Compact scan summary (package and outcome counts), echoed on edge-case batches for content-only clients.'}}, 'additionalProperties': False}
osv_query_package
Osv Query Package
Query known vulnerabilities for a single package version across any supported ecosystem. Returns all matching OSV advisories with severity (CVSS vectors), CVE aliases, affected version ranges, and the fixed versions listed for the queried package. Use osv_list_ecosystems to validate the ecosystem string before querying — ecosystem strings are case-sensitive exact matches and an invalid value returns an error, not empty results.
Nur Lesen Idempotent
Eingabeschema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['name', 'ecosystem', 'version'], 'properties': {'name': {'type': 'string', 'pattern': '\\S', 'description': 'Package name as it appears in the ecosystem (e.g. "express", "requests", "serde"). Case-sensitive.'}, 'version': {'type': 'string', 'pattern': '\\S', 'description': 'Package version to check (e.g. "4.17.1", "3.1.4", "1.0.0"). Must be an exact version string, not a range.'}, 'ecosystem': {'type': 'string', 'pattern': '\\S', 'description': 'Ecosystem identifier. Must be an exact match (case-sensitive). Use osv_list_ecosystems to see valid values. Examples: "npm", "PyPI", "crates.io", "Go", "Maven", "NuGet".'}}, 'additionalProperties': False}
Ausgabeschema
{'type': 'object', 'anyOf': [{'not': {'required': ['error']}, 'required': ['vulns', 'truncated', 'queryMeta']}, {'required': ['error']}], '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'error': {'type': 'object', 'required': ['code', 'message'], 'properties': {'code': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': -9007199254740991, 'description': 'JSON-RPC error code for this failure.'}, 'data': {'type': 'object', 'properties': {'reason': {'type': 'string', 'examples': ['invalid_ecosystem'], 'description': 'Machine-readable failure mode. Declared by this tool: `invalid_ecosystem`: The ecosystem string is not recognized by OSV. Ecosystem names are case-sensitive exact matches. Other values are possible when a failure originates below the handler.'}, 'recovery': {'type': 'object', 'required': ['hint'], 'properties': {'hint': {'type': 'string'}}, 'description': 'Actionable next step for the caller.', 'additionalProperties': {}}, 'retryable': {'type': 'boolean', 'description': 'Whether retrying may succeed.'}}, 'additionalProperties': {}}, 'message': {'type': 'string', 'description': 'Human-readable description of what went wrong.'}}, 'description': 'Present when the call failed. Absent on success.', 'additionalProperties': {}}, 'vulns': {'type': 'array', 'items': {'type': 'object', 'required': ['id', 'summary', 'aliases', 'severity', 'severityLabel', 'severitySource', 'fixedVersions', 'affectedRanges', 'cweIds', 'published', 'modified'], 'properties': {'id': {'type': 'string', 'description': 'OSV vulnerability ID (e.g. "GHSA-29mw-wpgm-hmr9", "PYSEC-2024-1"). Pass to osv_get_vulnerability to retrieve the full advisory record.'}, 'cweIds': {'type': 'array', 'items': {'type': 'string', 'description': 'A CWE ID string.'}, 'description': 'CWE weakness IDs (e.g. ["CWE-79", "CWE-94"]). Populated on GHSA-sourced records; empty otherwise.'}, 'aliases': {'type': 'array', 'items': {'type': 'string', 'description': 'A CVE ID or other alias.'}, 'description': 'Alternative IDs â\x80\x94 typically CVE IDs (e.g. ["CVE-2020-28500"]). Accepted by nist-nvd-mcp-server for CVSS scores, EPSS, and CISA KEV status.'}, 'summary': {'type': 'string', 'description': 'One-line vulnerability description.'}, 'modified': {'type': 'string', 'description': 'ISO 8601 timestamp of last modification.'}, 'severity': {'type': 'array', 'items': {'type': 'object', 'required': ['type', 'score'], 'properties': {'type': {'type': 'string', 'description': 'Severity type: "CVSS_V3", "CVSS_V4", "CVSS_V2", or "Ubuntu".'}, 'score': {'type': 'string', 'description': 'CVSS vector string (e.g. "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"), or the Ubuntu priority (e.g. "medium") for type "Ubuntu".'}}, 'description': 'One record-level severity entry.', 'additionalProperties': False}, 'description': 'Record-level severity entries (CVSS vectors, Ubuntu priorities). Empty for advisories not yet scored and for advisories that score each affected package separately â\x80\x94 severitySource then carries the queried package entry used.'}, 'published': {'type': 'string', 'description': 'ISO 8601 timestamp when the advisory was published.'}, 'fixedVersions': {'type': 'array', 'items': {'type': 'string', 'description': 'A version that fixes the vulnerability for the queried package.'}, 'description': "Every fixed version the advisory lists for the queried package, in record order. A multi-interval range contributes one per interval (typically one per release line); affectedRanges shows which interval each one closes. Excludes other packages' fixes and GIT commits. Empty when the advisory lists no fix for this package."}, 'severityLabel': {'type': ['string', 'null'], 'description': 'Severity label ("LOW", "MODERATE", "HIGH", "CRITICAL") from the first source that yields one: database_specific.severity, an Ubuntu priority, then the highest CVSS v3/v4 score (0.1â\x80\x933.9 LOW, 4.0â\x80\x936.9 MODERATE, 7.0â\x80\x938.9 HIGH, 9.0â\x80\x9310.0 CRITICAL). Uses the queried package\'s affected-level severity entries when the record-level list is empty. Null when no source yields a label.'}, 'affectedRanges': {'type': 'array', 'items': {'type': 'object', 'required': ['packageName', 'ecosystem', 'rangeType'], 'properties': {'repo': {'type': 'string', 'description': 'Source repository URL for GIT ranges. Absent on version ranges.'}, 'fixed': {'type': 'string', 'description': 'The last "fixed" event of this range (convenience view â\x80\x94 a multi-interval range carries several; see events[]).'}, 'events': {'type': 'array', 'items': {'type': 'object', 'required': ['type', 'value'], 'properties': {'type': {'type': 'string', 'description': 'Event boundary type: "introduced", "fixed", "last_affected", or "limit".'}, 'value': {'type': 'string', 'description': 'Version string or commit identifier at this boundary.'}}, 'description': 'One ordered range event.', 'additionalProperties': False}, 'description': 'Ordered event boundaries for this range â\x80\x94 the loss-free view preserving multiple introduced/fixed pairs the scalar fields collapse.'}, 'versions': {'type': 'array', 'items': {'type': 'string', 'description': 'An explicitly-listed affected version.'}, 'description': 'Explicit affected versions listed on this package entry. Absent or empty when affected versions are expressed only as ranges.'}, 'ecosystem': {'type': 'string', 'description': 'Affected package ecosystem. Empty for source-only advisory ranges.'}, 'rangeType': {'type': 'string', 'description': '"SEMVER", "ECOSYSTEM", or "GIT".'}, 'introduced': {'type': 'string', 'description': 'First affected version (convenience view â\x80\x94 see events[]).'}, 'packageName': {'type': 'string', 'description': 'Affected package name (may differ from queried name for umbrella advisories). Empty for source-only advisory ranges.'}, 'lastAffected': {'type': 'string', 'description': 'Last affected version. Present when no fix exists (convenience view â\x80\x94 see events[]).'}}, 'description': 'One affected version range.', 'additionalProperties': False}, 'description': 'Version ranges affected by this vulnerability.'}, 'severitySource': {'anyOf': [{'type': 'object', 'required': ['type', 'score'], 'properties': {'type': {'enum': ['database_specific', 'Ubuntu', 'CVSS_V3', 'CVSS_V4'], 'type': 'string', 'description': 'Source kind: the database_specific.severity label, an Ubuntu priority, or a CVSS vector.'}, 'score': {'type': 'string', 'description': 'The published value the label came from: the database_specific.severity text, the Ubuntu priority, or the CVSS vector.'}, 'computedScore': {'type': 'number', 'description': 'CVSS score computed from the vector as published: a CVSS 4.0 vector over every metric group it carries (threat and environmental included), a CVSS 3.x vector with its temporal metrics. Present only for CVSS sources.'}}, 'additionalProperties': False}, {'type': 'null'}], 'description': 'The severity entry severityLabel was derived from. Null exactly when the label is.'}}, 'description': 'One vulnerability record.', 'additionalProperties': False}, 'description': 'Vulnerabilities matching this package version. An empty array means no known vulnerabilities ONLY when truncated is false.'}, 'notice': {'type': 'string', 'description': 'Present on the clean path â\x80\x94 confirms no known vulnerabilities for the queried package.'}, 'queryMeta': {'type': 'object', 'required': ['package', 'ecosystem', 'version', 'vulnCount'], 'properties': {'package': {'type': 'string', 'description': 'Queried package name.'}, 'version': {'type': 'string', 'description': 'Queried version.'}, 'ecosystem': {'type': 'string', 'description': 'Queried ecosystem.'}, 'vulnCount': {'type': 'number', 'description': 'Number of vulnerabilities found.'}}, 'description': 'Query parameters as submitted.', 'additionalProperties': False}, 'truncated': {'type': 'boolean', 'description': 'True when OSV returned more result pages than the fetch cap could follow â\x80\x94 the vulnerability list may be INCOMPLETE. A truncated empty list is NOT a clean result; raise OSV_QUERY_MAX_PAGES or narrow the query.'}, 'effectiveQuery': {'type': 'string', 'description': 'The package@version (ecosystem) tuple as queried, echoed for content-only clients.'}}, 'additionalProperties': False}
Geändert
osv_query_batch
27. September 2026 02:44
Geändert
osv_get_vulnerability
27. September 2026 02:44
Geändert
osv_query_package
27. September 2026 02:44
Geändert
osv_list_ecosystems
27. September 2026 02:44
Geändert
osv_query_batch
21. September 2026 02:50
Geändert
osv_get_vulnerability
21. September 2026 02:50
Geändert
osv_query_package
21. September 2026 02:50
Hinzugefügt
osv_query_batch
17. September 2026 12:41
Hinzugefügt
osv_get_vulnerability
17. September 2026 12:41
Hinzugefügt
osv_query_package
17. September 2026 12:41
Hinzugefügt
osv_list_ecosystems
17. September 2026 12:41

hyperion

com.thetempleofdoom.hyperion/hyperion

Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…

Vee3

io.github.Vee3io/vee3

Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…

IA-QA — 130+ QA & Dev Tools for AI Agents

io.github.JcJamet/ia-qa-toolbox

Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…

validoria-mcp

com.validoria/validoria-mcp

Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…

HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data

io.github.Its-fortunatefolly/hubvibe

Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…

developer-tools

net.programmes/developer-tools

Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…

Qiniso

io.github.qinisolabs/qiniso

Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…

ContrastAPI

com.contrastcyber/api

Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…