VulnMCP logo

VulnMCP

Unclaimed

by vulnerability-lookup

A modular MCP server providing AI-driven vulnerability management skills, including severity classification and automated insights.

Install

$claude mcp add vulnmcp -- poetry --directory /path/to/VulnMCP run vulnmcp

Set up this server

This server needs project-specific setup. Follow the project instructions; no reusable public launch command is available yet.

Project instructions
cpecvsscwemcpvulnerabilityvulnerability-lookup

More in AI & ML

Browse the full directory

Unclaimed listing

Is this your MCP server?

This listing was auto-indexed from the public record. Claim it to edit the page, set compatibility and unlock growth tools. Takes under two minutes.

Claim this server

Security profile

Claimed and verified servers get a weekly static scan that shows what the code can reach: external services, environment variables, shell commands, agent configuration folders, plus any dependencies with known advisories. Claim this listing to get one. How the security profile works

16 of 16 tools

Documented tools (16)

From project documentation. A server handshake does not verify each tool’s description or behavior.

classify_cwe

Predict CWE categories from a vulnerability description. Returns top-5 predictions with parent CWE mapping.

classify_severity

Classify vulnerability severity (low/medium/high/critical) from a text description. Supports English, Chinese, and Russian with auto-detection.

create_sighting

Create a new sighting for a vulnerability (requires API permissions on most instances).

get_gna_entry

Get a specific GNA entry by numeric ID or exact short name.

get_most_sighted_vulnerabilities

Retrieve a ranking of vulnerabilities by sighting activity to help prioritize important issues.

get_recent_vulnerabilities_by_cwe

Fetch the 3 most recent CVEs for a given CWE ID.

get_vulnerability

Look up a specific vulnerability by ID (e.g. CVE-2025-14847) with optional comments, sightings, bundles, linked vulnerabilities, and KEV enrichment.

guess_cpes

Query cpe-guesser with product keywords to infer likely CPE identifiers.

list_gcve_references

List GCVE references including KEV catalog UUIDs for use with listkeventries.

list_gna_entries

List all Global Numbering Authorities (GNA) from the GCVE registry.

list_kev_entries

List and filter KEV catalog entries by vulnerability ID, status reason, exploited flag, date range, author, or origin catalog UUID.

search_bundles

Search curated vulnerability bundles (grouped CVEs for a campaign, product, or incident), with filters by vulnerability ID or author.

search_comments

Search community comments related to vulnerabilities, with filters by vulnerability ID or author.

search_gna

Search GNA entries by name (case-insensitive substring match).

search_sightings

Search vulnerability sightings (seen/exploited/patched/etc.) with filters to identify what is actively discussed or abused.

search_vulnerabilities

Search vulnerabilities with filters: source, CWE, product, date range, pagination, and optional KEV-aware prioritization.

Tool change history

Compared across complete checks of the same configuration. Tools were listed, not invoked. Input-schema changes are not measured here.

No complete tool checks yet.

FAQ

Questions about Vuln MCP Server

How do I connect Vuln MCP Server to Claude?
The listing records `claude mcp add vulnmcp -- poetry --directory /path/to/VulnMCP run vulnmcp` as its setup step. Run it, then follow the repository's instructions for the client configuration; the listing names Claude Desktop, Claude Code as compatible clients.
Is Vuln MCP Server free?
The listed licence is AGPL-3.0. Check the upstream terms for permitted use and commercial requirements; a public repository does not by itself mean the software is free or open source. Connected APIs and hosted services may have separate charges.
What can Vuln MCP Server do?
Vuln MCP Server documents 16 tools to the agent, including classify_cwe, classify_severity, create_sighting. The descriptions above come from project documentation. A live handshake does not test individual tool behavior.