nist-nvd-mcp-server

Search and audit NIST NVD CVEs by keyword, severity, CWE, CISA KEV status, and CPE.

我该使用它吗

质量与安全性

A
描述质量
100%
模式完整度
93%
命名质量
80%
投毒风险
100%
权限匹配度
100%
协议合规性
100%

基于对工具定义和协议合规性的自动分析。

上下文开销

~9,215token 数(工具定义)
~22.4 KB典型响应大小
对注意力有显著影响(占 128k 上下文窗口的 7.20%)

这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。

安装

一键安装

将以下内容添加到你的 `claude_desktop_config.json` 文件中:

{
  "mcpServers": {
    "nist-nvd-mcp-server": {
      "command": "bun",
      "args": [
        "@cyanheads/nist-nvd-mcp-server"
      ]
    }
  }
}

可运行的软件包

npm@cyanheads/nist-nvd-mcp-server0.3.1streamable-http

远程端点

https://nist-nvd.caseyjhand.com/mcpstreamable-http

它能做什么

工具清单

工具(5)

🟢 只读🟡 写入🔴 删除⚪ 未知
🟢nvd_get_cve(cveIds, brief, includeReferences, allLanguages)

Fetch one or more CVEs by ID from the NIST National Vulnerability Database. Returns CVSS scores across all available versions (v2.0, v3.0, v3.1, v4.0), CWE weakness classifications, affected CPE configurations, CISA KEV fields, and references. Up to 100 CVE IDs per call. For bulk lookups of more than 10 IDs, use brief: true — full records for 100 CVEs can exceed 1MB and exhaust context budgets.

输入模式

{
  "type": "object",
  "properties": {
    "cveIds": {
      "anyOf": [
        {
          "type": "string",
          "description": "A single CVE ID (e.g., \"CVE-2021-44228\")."
        },
        {
          "minItems": 1,
          "maxItems": 100,
          "type": "array",
          "items": {
            "type": "string"
          },
          "description": "An array of CVE IDs — at least 1, up to 100 per call."
        }
      ],
      "description": "One CVE ID or an array of up to 100 CVE IDs to fetch."
    },
    "brief": {
      "default": false,
      "description": "When true, returns trimmed records (ID, status, top CVSS score, KEV name, published date, and a truncated description) instead of full detail. Recommended for batches of more than 10 IDs.",
      "type": "boolean"
    },
    "includeReferences": {
      "default": true,
      "description": "When false, omits the references array to reduce response size.",
      "type": "boolean"
    },
    "allLanguages": {
      "default": false,
      "description": "When true, keeps every localized description NVD supplies on each record, and full records render all of them. Default keeps English only, falling back to whatever exists if a record has no English entry. Brief records always carry a single truncated description.",
      "type": "boolean"
    }
  },
  "required": [
    "cveIds"
  ],
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false
}

输出模式

{
  "type": "object",
  "properties": {
    "brief": {
      "type": "boolean",
      "description": "Whether brief or full records were returned."
    },
    "cves": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "cveId": {
            "type": "string",
            "description": "CVE identifier (e.g., \"CVE-2021-44228\")."
          },
          "vulnStatus": {
            "type": "string",
            "description": "NVD analysis status."
          },
          "published": {
            "type": "string",
            "description": "ISO 8601 publication datetime."
          },
          "lastModified": {
            "type": "string",
            "description": "ISO 8601 last-modified datetime."
          },
          "descriptions": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "lang": {
                  "type": "string",
                  "description": "Language code."
                },
                "value": {
                  "type": "string",
                  "description": "CVE description."
                }
              },
              "required": [
                "lang",
                "value"
              ],
              "additionalProperties": false,
              "description": "One localized CVE description."
            },
            "description": "CVE descriptions by language."
          },
          "cvssScores": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "version": {
                  "type": "string",
                  "description": "CVSS version (e.g., \"2.0\", \"3.1\", \"4.0\")."
                },
                "sourceType": {
                  "type": "string",
                  "description": "Score source: \"Primary\" = NVD, \"Secondary\" = CNA."
                },
                "baseScore": {
                  "type": "number",
                  "description": "Base score (0.0–10.0)."
                },
                "severity": {
                  "type": "string",
                  "description": "Severity label: CRITICAL, HIGH, MEDIUM, or LOW."
                },
                "vectorString": {
                  "description": "CVSS vector string.",
                  "type": "string"
                }
              },
              "required": [
                "version",
                "sourceType",
                "baseScore",
                "severity"
              ],
              "additionalProperties": false,
              "description": "One CVSS score entry."
            },
            "description": "All available CVSS scores across versions."
          },
          "severity": {
            "description": "Top severity. Absent if no CVSS scores present.",
            "type": "object",
            "properties": {
              "label": {
                "type": "string",
                "description": "Highest severity label across all CVSS versions."
              },
              "score": {
                "type": "number",
                "description": "Highest base score (0.0–10.0)."
              },
              "fromVersion": {
                "type": "string",
                "description": "Which CVSS version this top score came from."
              }
            },
            "required": [
              "label",
              "score",
              "fromVersion"
            ],
            "additionalProperties": false
          },
          "weaknesses": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "source": {
                  "type": "string",
                  "description": "Who classified the weakness, as the contributor name NVD publishes for it (e.g. \"CVE\", \"CISA-ADP\"). Contributors NVD identifies by email address keep that address (e.g. \"[email protected]\"); an identifier absent from NVD's contributor dictionary passes through as its raw value."
                },
                "cweIds": {
                  "type": "array",
                  "items": {
                    "type": "string",
                    "description": "One CWE identifier."
                  },
                  "description": "CWE identifiers for this source."
                }
              },
              "required": [
                "source",
                "cweIds"
              ],
              "additionalProperties": false,
              "description": "One weakness classification entry."
            },
            "description": "CWE weakness classifications."
          },
          "configurationNodes": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "groupIndex": {
                  "type": "number",
                  "description": "Zero-based index of the NVD configuration group this node belongs to. Nodes sharing a groupIndex were siblings in one group, combined by groupOperator."
                },
                "groupOperator": {
                  "description": "Logical operator (AND/OR) combining this node with its sibling nodes in the same group. An \"AND\" means every node in the group must match for the CVE to apply — e.g. a firmware node and the hardware it runs on. Absent when the group has nothing to combine.",
                  "type": "string"
                },
                "nodeOperator": {
                  "description": "Logical operator (AND/OR) combining this node's own criteria below. Absent when the node has nothing to combine.",
                  "type": "string"
                },
                "cpeMatch": {
                  "type": "array",
                  "items": {
                    "type": "object",
                    "properties": {
                      "vulnerable": {
                        "type": "boolean",
                        "description": "Whether this CPE is the vulnerable component or only the context it runs in."
                      },
                      "criteria": {
                        "type": "string",
                        "description": "CPEv2.3 match criteria string."
                      },
                      "versionStartIncluding": {
                        "description": "Inclusive lower version bound.",
                        "type": "string"
                      },
                      "versionStartExcluding": {
                        "description": "Exclusive lower version bound.",
                        "type": "string"
                      },
                      "versionEndIncluding": {
                        "description": "Inclusive upper version bound.",
                        "type": "string"
                      },
                      "versionEndExcluding": {
                        "description": "Exclusive upper version bound.",
                        "type": "string"
                      }
                    },
                    "required": [
                      "vulnerable",
                      "criteria"
                    ],
                    "additionalProperties": false,
                    "description": "One CPE match criterion."
                  },
                  "description": "This node's CPE match criteria, in the order NVD lists them."
                }
              },
              "required": [
                "groupIndex",
                "cpeMatch"
              ],
              "additionalProperties": false,
              "description": "One affected product configuration node, tagged with the group it came from."
            },
            "description": "Affected product configuration nodes. NVD nests these under configuration groups; the groups are represented by groupIndex so each node's own criteria stay together."
          },
          "references": {
            "description": "External references.",
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "url": {
                  "type": "string",
                  "description": "Reference URL."
                },
                "source": {
                  "description": "Who contributed the reference, as the contributor name NVD publishes for it (e.g. \"CVE\", \"CISA-ADP\"). Contributors NVD identifies by email address keep that address (e.g. \"[email protected]\"); an identifier absent from NVD's contributor dictionary passes through as its raw value.",
                  "type": "string"
                },
                "tags": {
                  "description": "Classification tags.",
                  "type": "array",
                  "items": {
                    "type": "string",
                    "description": "One classification tag."
                  }
                }
              },
              "required": [
                "url"
              ],
              "additionalProperties": false,
              "description": "One external reference."
            }
          },
          "cisaKev": {
            "description": "CISA KEV fields. Present only when CVE is in the KEV catalog.",
            "type": "object",
            "properties": {
              "exploitAddDate": {
                "type": "string",
                "description": "Date added to CISA KEV catalog."
              },
              "actionDueDate": {
                "type": "string",
                "description": "Federal agency remediation deadline."
              },
              "requiredAction": {
                "type": "string",
                "description": "Required remediation steps."
              },
              "vulnerabilityName": {
                "type": "string",
                "description": "CISA's vulnerability name."
              }
            },
            "required": [
              "exploitAddDate",
              "actionDueDate",
              "requiredAction",
              "vulnerabilityName"
            ],
            "additionalProperties": false
          },
          "description": {
            "description": "Opening 200 characters of the English CVE description, truncated with an ellipsis when longer. Enough to tell one result from another; call nvd_get_cve for the full text. Absent when NVD carries no description for the record.",
            "type": "string"
          },
          "cisaVulnerabilityName": {
            "description": "CISA KEV vulnerability name. Present only when in the KEV catalog.",
            "type": "string"
          }
        },
        "required": [
          "cveId",
          "vulnStatus",
          "published"
        ],
        "additionalProperties": {},
        "description": "One CVE record. Every field beyond cveId, vulnStatus, and published depends on the mode: full mode (the default) carries all of them except description and cisaVulnerabilityName, which are the brief-mode substitutes for descriptions and cisaKev."
      },
      "description": "CVE records — full detail by default, trimmed rows when brief is true."
    },
    "requested": {
      "type": "number",
      "description": "Number of CVE IDs requested."
    },
    "returned": {
      "type": "number",
      "description": "Number of CVE records returned."
    },
    "missingIds": {
      "description": "CVE IDs requested but not found in NVD. Absent when all IDs matched.",
      "type": "array",
      "items": {
        "type": "string",
        "description": "A CVE ID not found in NVD."
      }
    },
    "error": {
      "description": "Present when the call failed. Absent on success.",
      "type": "object",
      "properties": {
        "code": {
          "type": "integer",
          "minimum": -9007199254740991,
          "maximum": 9007199254740991,
          "description": "JSON-RPC error code for this failure."
        },
        "message": {
          "type": "string",
          "description": "Human-readable description of what went wrong."
        },
        "data": {
          "type": "object",
          "properties": {
            "reason": {
              "type": "string",
              "description": "Machine-readable failure mode. Declared by this tool: `invalid_cve_id_format`: One or more CVE IDs fail format validation (NVD returns HTTP 404 for malformed IDs). `cve_not_found`: A valid-format CVE ID returns no results — the ID is well-formed but does not exist in NVD. `rate_limited`: NVD returned HTTP 403 indicating the rate limit was exceeded. Other values are possible when a failure originates below the handler.",
              "examples": [
                "invalid_cve_id_format",
                "cve_not_found",
                "rate_limited"
              ]
            },
            "recovery": {
              "description": "Actionable next step for the caller.",
              "type": "object",
              "properties": {
                "hint": {
                  "type": "string"
                }
              },
              "required": [
                "hint"
              ],
              "additionalProperties": {}
            },
            "retryable": {
              "description": "Whether retrying may succeed.",
              "type": "boolean"
            }
          },
          "additionalProperties": {}
        }
      },
      "required": [
        "code",
        "message"
      ],
      "additionalProperties": {}
    }
  },
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false,
  "anyOf": [
    {
      "not": {
        "required": [
          "error"
        ]
      },
      "required": [
        "brief",
        "cves",
        "requested",
        "returned"
      ]
    },
    {
      "required": [
        "error"
      ]
    }
  ]
}
🟢nvd_search_cves(keyword, exactPhrase, severity, severityVersion, cweId, ...)

Search CVEs by keyword, severity, CWE, date range, or CISA KEV status. The primary discovery tool for vulnerability surveillance and triage workflows. pubDays and lastModDays are convenience shorthands that expand to date pairs; values over 120 days are clamped to the NVD maximum and reported in the response enrichment. Returns brief summaries — call nvd_get_cve for full detail on specific IDs. At least one filter is recommended; omitting all filters returns CVEs in default NVD index order (oldest first by CVE ID).

输入模式

{
  "type": "object",
  "properties": {
    "keyword": {
      "description": "Full-text search across CVE descriptions (AND-semantics across words).",
      "type": "string"
    },
    "exactPhrase": {
      "default": false,
      "description": "When true, keyword matches as an exact phrase rather than ANDing its words independently. Requires keyword.",
      "type": "boolean"
    },
    "severity": {
      "description": "Filter to CVEs in exactly this CVSS severity band — NVD matches the one band, not a floor. Covering several bands (e.g. HIGH and CRITICAL) takes one call per band.",
      "type": "string",
      "enum": [
        "LOW",
        "MEDIUM",
        "HIGH",
        "CRITICAL"
      ]
    },
    "severityVersion": {
      "default": "v3",
      "description": "CVSS version to use for the severity filter. Default: v3 (maps to cvssV3Severity).",
      "type": "string",
      "enum": [
        "v2",
        "v3",
        "v4"
      ]
    },
    "cweId": {
      "description": "Filter by CWE weakness ID (e.g., \"CWE-79\", \"NVD-CWE-Other\").",
      "type": "string"
    },
    "pubDays": {
      "description": "CVEs published in the last N days (max 120; values over 120 are clamped). Mutually exclusive with pubStartDate/pubEndDate.",
      "type": "integer",
      "exclusiveMinimum": 0,
      "maximum": 9007199254740991
    },
    "lastModDays": {
      "description": "CVEs last modified in the last N days (max 120; values over 120 are clamped). Mutually exclusive with lastModStartDate/lastModEndDate.",
      "type": "integer",
      "exclusiveMinimum": 0,
      "maximum": 9007199254740991
    },
    "pubStartDate": {
      "description": "ISO 8601 datetime for publication range start. Both pubStartDate and pubEndDate required together. Mutually exclusive with pubDays.",
      "type": "string"
    },
    "pubEndDate": {
      "description": "ISO 8601 datetime for publication range end. Both pubStartDate and pubEndDate required together.",
      "type": "string"
    },
    "lastModStartDate": {
      "description": "ISO 8601 datetime for last-modified range start. Both required together. Mutually exclusive with lastModDays.",
      "type": "string"
    },
    "lastModEndDate": {
      "description": "ISO 8601 datetime for last-modified range end. Both required together.",
      "type": "string"
    },
    "kevOnly": {
      "default": false,
      "description": "When true, filters results to CVEs in the CISA Known Exploited Vulnerabilities catalog.",
      "type": "boolean"
    },
    "noRejected": {
      "default": true,
      "description": "When true (default), excludes CVEs with REJECT/Rejected status.",
      "type": "boolean"
    },
    "limit": {
      "default": 20,
      "description": "Maximum number of results to return (default 20, max 2000).",
      "type": "integer",
      "minimum": 1,
      "maximum": 2000
    },
    "offset": {
      "default": 0,
      "description": "Zero-based page offset for pagination.",
      "type": "integer",
      "minimum": 0,
      "maximum": 9007199254740991
    }
  },
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false
}

输出模式

{
  "type": "object",
  "properties": {
    "cves": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "cveId": {
            "type": "string",
            "description": "CVE identifier (e.g., \"CVE-2021-44228\")."
          },
          "vulnStatus": {
            "type": "string",
            "description": "NVD analysis status."
          },
          "published": {
            "type": "string",
            "description": "ISO 8601 publication datetime."
          },
          "description": {
            "description": "Opening 200 characters of the English CVE description, truncated with an ellipsis when longer. Enough to tell one result from another; call nvd_get_cve for the full text. Absent when NVD carries no description for the record.",
            "type": "string"
          },
          "severity": {
            "description": "Top severity. Absent if no CVSS scores are present.",
            "type": "object",
            "properties": {
              "label": {
                "type": "string",
                "description": "Highest severity label across all CVSS versions."
              },
              "score": {
                "type": "number",
                "description": "Highest base score (0.0–10.0)."
              },
              "fromVersion": {
                "type": "string",
                "description": "CVSS version this score came from."
              }
            },
            "required": [
              "label",
              "score",
              "fromVersion"
            ],
            "additionalProperties": false
          },
          "filteredSeverity": {
            "description": "Severity at the CVSS version the severity filter matched this CVE on. Present only when a severity filter was supplied and that version disagrees with the cross-version top severity above — e.g. a CVE scored v2 10.0 (HIGH) and v3.1 9.8 (CRITICAL) headlines as HIGH but matched a CRITICAL v3 query on the 9.8.",
            "type": "object",
            "properties": {
              "label": {
                "type": "string",
                "description": "Severity label at the CVSS version the severity filter used."
              },
              "score": {
                "type": "number",
                "description": "Base score at that CVSS version (0.0–10.0)."
              },
              "fromVersion": {
                "type": "string",
                "description": "The CVSS version the severity filter matched on."
              }
            },
            "required": [
              "label",
              "score",
              "fromVersion"
            ],
            "additionalProperties": false
          },
          "cisaVulnerabilityName": {
            "description": "CISA KEV vulnerability name. Present only when in the KEV catalog.",
            "type": "string"
          }
        },
        "required": [
          "cveId",
          "vulnStatus",
          "published"
        ],
        "additionalProperties": false,
        "description": "Brief summary for one matching CVE."
      },
      "description": "Matching CVE summaries. Call nvd_get_cve for full detail on specific IDs."
    },
    "totalCount": {
      "type": "number",
      "description": "Total matching CVEs in NVD before pagination."
    },
    "returned": {
      "type": "number",
      "description": "Number of CVEs returned in this response."
    },
    "offset": {
      "type": "number",
      "description": "Page offset used in this query."
    },
    "datesClamped": {
      "description": "Entries for any pubDays/lastModDays values that exceeded 120 and were auto-clamped. Absent when no clamping occurred.",
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "param": {
            "type": "string",
            "description": "The parameter that was clamped (pubDays or lastModDays)."
          },
          "original": {
            "type": "number",
            "description": "The original value supplied."
          },
          "clamped": {
            "type": "number",
            "description": "The clamped value used (max 120)."
          }
        },
        "required": [
          "param",
          "original",
          "clamped"
        ],
        "additionalProperties": false,
        "description": "A single clamping event for one convenience date parameter."
      }
    },
    "filtersApplied": {
      "description": "The non-default filters this query actually applied — the ones that can account for an empty or unexpectedly narrow result set. Absent when the query ran unfiltered, which is itself the answer when a result set is unexpectedly broad.",
      "type": "object",
      "properties": {
        "keyword": {
          "description": "The keyword filter that was applied.",
          "type": "string"
        },
        "exactPhrase": {
          "description": "Present as true when the keyword was matched as an exact phrase rather than word-by-word.",
          "type": "boolean"
        },
        "severity": {
          "description": "The exact CVSS severity band that was applied — results are limited to this band alone, so higher bands are not included.",
          "type": "string"
        },
        "severityVersion": {
          "description": "The CVSS version the severity filter matched on. Present only alongside severity.",
          "type": "string"
        },
        "cweId": {
          "description": "The CWE weakness filter that was applied.",
          "type": "string"
        },
        "kevOnly": {
          "description": "Present as true when results were limited to the CISA KEV catalog.",
          "type": "boolean"
        },
        "noRejected": {
          "description": "Present as false when rejected CVEs were left in the results.",
          "type": "boolean"
        }
      },
      "additionalProperties": false
    },
    "notice": {
      "description": "Guidance when no CVEs were returned — distinguishes a query nothing matched from an offset past the result set from an empty page NVD returned inside a range it says has matches — or, on a partial page, the offset that reaches the next one.",
      "type": "string"
    },
    "error": {
      "description": "Present when the call failed. Absent on success.",
      "type": "object",
      "properties": {
        "code": {
          "type": "integer",
          "minimum": -9007199254740991,
          "maximum": 9007199254740991,
          "description": "JSON-RPC error code for this failure."
        },
        "message": {
          "type": "string",
          "description": "Human-readable description of what went wrong."
        },
        "data": {
          "type": "object",
          "properties": {
            "reason": {
              "type": "string",
              "description": "Machine-readable failure mode. Declared by this tool: `exact_phrase_without_keyword`: exactPhrase was set without a keyword. It selects how keyword matches and has nothing to modify on its own; NVD rejects the underlying flag on the same grounds. `mutually_exclusive_params`: Both pubDays and pubStartDate/pubEndDate provided, or both lastModDays and lastModStartDate/lastModEndDate. `missing_date_pair`: Only one of pubStartDate/pubEndDate (or lastModStartDate/lastModEndDate) was provided — NVD requires both. `date_range_inverted`: The end date is before the start date. `date_range_exceeds_max`: Explicit pubStartDate/pubEndDate or lastModStartDate/lastModEndDate span more than 120 days. `invalid_date_format`: A date string provided for pubStartDate, pubEndDate, lastModStartDate, or lastModEndDate is not a valid ISO 8601 datetime. `invalid_severity_for_version`: severity=\"CRITICAL\" was specified with severityVersion=\"v2\" — CVSS v2 has no CRITICAL tier. `rate_limited`: NVD returned HTTP 403 indicating the rate limit was exceeded. Other values are possible when a failure originates below the handler.",
              "examples": [
                "exact_phrase_without_keyword",
                "mutually_exclusive_params",
                "missing_date_pair",
                "date_range_inverted",
                "date_range_exceeds_max",
                "invalid_date_format",
                "invalid_severity_for_version",
                "rate_limited"
              ]
            },
            "recovery": {
              "description": "Actionable next step for the caller.",
              "type": "object",
              "properties": {
                "hint": {
                  "type": "string"
                }
              },
              "required": [
                "hint"
              ],
              "additionalProperties": {}
            },
            "retryable": {
              "description": "Whether retrying may succeed.",
              "type": "boolean"
            }
          },
          "additionalProperties": {}
        }
      },
      "required": [
        "code",
        "message"
      ],
      "additionalProperties": {}
    }
  },
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false,
  "anyOf": [
    {
      "not": {
        "required": [
          "error"
        ]
      },
      "required": [
        "cves",
        "totalCount",
        "returned",
        "offset"
      ]
    },
    {
      "required": [
        "error"
      ]
    }
  ]
}
🟢nvd_audit_cpe(cpeName, virtualMatchString, versionStart, versionStartType, versionEnd, ...)

Find all CVEs affecting a specific product and version using CPE (Common Platform Enumeration). Requires either an exact CPE name (cpeName) or a partial match string (virtualMatchString) with optional version range bounds. With cpeName, NVD scopes results to configurations where the product is directly vulnerable, not merely referenced as a dependency. Use nvd_search_cpes first to resolve the correct CPE string for a product. Returns full CVE records.

输入模式

{
  "type": "object",
  "properties": {
    "cpeName": {
      "description": "Full CPEv2.3 name (e.g., \"cpe:2.3:a:apache:http_server:2.4.51:*:*:*:*:*:*:*\"). NVD adds isVulnerable automatically. Mutually exclusive with virtualMatchString.",
      "type": "string"
    },
    "virtualMatchString": {
      "description": "Partial CPE match pattern (e.g., \"cpe:2.3:a:apache:http_server:*\"). Use with versionStart/versionEnd for version range audits. Mutually exclusive with cpeName.",
      "type": "string"
    },
    "versionStart": {
      "description": "Lower version bound. Requires virtualMatchString.",
      "type": "string"
    },
    "versionStartType": {
      "default": "including",
      "description": "Whether the lower version bound is inclusive or exclusive.",
      "type": "string",
      "enum": [
        "including",
        "excluding"
      ]
    },
    "versionEnd": {
      "description": "Upper version bound. Requires virtualMatchString.",
      "type": "string"
    },
    "versionEndType": {
      "default": "including",
      "description": "Whether the upper version bound is inclusive or exclusive.",
      "type": "string",
      "enum": [
        "including",
        "excluding"
      ]
    },
    "severityMin": {
      "description": "Filter out CVEs below this severity level. Applied after NVD returns the page, so it can only drop CVEs within limit — raise limit to widen what it sees.",
      "type": "string",
      "enum": [
        "LOW",
        "MEDIUM",
        "HIGH",
        "CRITICAL"
      ]
    },
    "allLanguages": {
      "default": false,
      "description": "When true, keeps every localized description NVD supplies on each record. Default keeps English only.",
      "type": "boolean"
    },
    "limit": {
      "default": 20,
      "description": "Maximum number of CVEs to return (default 20, max 2000).",
      "type": "integer",
      "minimum": 1,
      "maximum": 2000
    },
    "offset": {
      "default": 0,
      "description": "Zero-based page offset for pagination. Page through totalCount with a modest limit rather than raising limit — this tool returns full CVE records, so a large limit is a large response.",
      "type": "integer",
      "minimum": 0,
      "maximum": 9007199254740991
    }
  },
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false
}

输出模式

{
  "type": "object",
  "properties": {
    "cves": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "cveId": {
            "type": "string",
            "description": "CVE identifier (e.g., \"CVE-2021-44228\")."
          },
          "vulnStatus": {
            "type": "string",
            "description": "NVD analysis status."
          },
          "published": {
            "type": "string",
            "description": "ISO 8601 publication datetime."
          },
          "lastModified": {
            "type": "string",
            "description": "ISO 8601 last-modified datetime."
          },
          "descriptions": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "lang": {
                  "type": "string",
                  "description": "Language code."
                },
                "value": {
                  "type": "string",
                  "description": "CVE description."
                }
              },
              "required": [
                "lang",
                "value"
              ],
              "additionalProperties": false,
              "description": "One localized CVE description."
            },
            "description": "CVE descriptions by language."
          },
          "cvssScores": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "version": {
                  "type": "string",
                  "description": "CVSS version (e.g., \"2.0\", \"3.1\", \"4.0\")."
                },
                "sourceType": {
                  "type": "string",
                  "description": "Score source: \"Primary\" = NVD, \"Secondary\" = CNA."
                },
                "baseScore": {
                  "type": "number",
                  "description": "Base score (0.0–10.0)."
                },
                "severity": {
                  "type": "string",
                  "description": "Severity label: CRITICAL, HIGH, MEDIUM, or LOW."
                },
                "vectorString": {
                  "description": "CVSS vector string.",
                  "type": "string"
                }
              },
              "required": [
                "version",
                "sourceType",
                "baseScore",
                "severity"
              ],
              "additionalProperties": false,
              "description": "One CVSS score entry."
            },
            "description": "All available CVSS scores across versions."
          },
          "severity": {
            "description": "Top severity. Absent if no CVSS scores present.",
            "type": "object",
            "properties": {
              "label": {
                "type": "string",
                "description": "Highest severity label across all CVSS versions."
              },
              "score": {
                "type": "number",
                "description": "Highest base score (0.0–10.0)."
              },
              "fromVersion": {
                "type": "string",
                "description": "Which CVSS version this top score came from."
              }
            },
            "required": [
              "label",
              "score",
              "fromVersion"
            ],
            "additionalProperties": false
          },
          "weaknesses": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "source": {
                  "type": "string",
                  "description": "Who classified the weakness, as the contributor name NVD publishes for it (e.g. \"CVE\", \"CISA-ADP\"). Contributors NVD identifies by email address keep that address (e.g. \"[email protected]\"); an identifier absent from NVD's contributor dictionary passes through as its raw value."
                },
                "cweIds": {
                  "type": "array",
                  "items": {
                    "type": "string",
                    "description": "One CWE identifier."
                  },
                  "description": "CWE identifiers for this source."
                }
              },
              "required": [
                "source",
                "cweIds"
              ],
              "additionalProperties": false,
              "description": "One weakness classification entry."
            },
            "description": "CWE weakness classifications."
          },
          "configurationNodes": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "groupIndex": {
                  "type": "number",
                  "description": "Zero-based index of the NVD configuration group this node belongs to. Nodes sharing a groupIndex were siblings in one group, combined by groupOperator."
                },
                "groupOperator": {
                  "description": "Logical operator (AND/OR) combining this node with its sibling nodes in the same group. An \"AND\" means every node in the group must match for the CVE to apply — e.g. a firmware node and the hardware it runs on. Absent when the group has nothing to combine.",
                  "type": "string"
                },
                "nodeOperator": {
                  "description": "Logical operator (AND/OR) combining this node's own criteria below. Absent when the node has nothing to combine.",
                  "type": "string"
                },
                "cpeMatch": {
                  "type": "array",
                  "items": {
                    "type": "object",
                    "properties": {
                      "vulnerable": {
                        "type": "boolean",
                        "description": "Whether this CPE is the vulnerable component or only the context it runs in."
                      },
                      "criteria": {
                        "type": "string",
                        "description": "CPEv2.3 match criteria string."
                      },
                      "versionStartIncluding": {
                        "description": "Inclusive lower version bound.",
                        "type": "string"
                      },
                      "versionStartExcluding": {
                        "description": "Exclusive lower version bound.",
                        "type": "string"
                      },
                      "versionEndIncluding": {
                        "description": "Inclusive upper version bound.",
                        "type": "string"
                      },
                      "versionEndExcluding": {
                        "description": "Exclusive upper version bound.",
                        "type": "string"
                      }
                    },
                    "required": [
                      "vulnerable",
                      "criteria"
                    ],
                    "additionalProperties": false,
                    "description": "One CPE match criterion."
                  },
                  "description": "This node's CPE match criteria, in the order NVD lists them."
                }
              },
              "required": [
                "groupIndex",
                "cpeMatch"
              ],
              "additionalProperties": false,
              "description": "One affected product configuration node, tagged with the group it came from."
            },
            "description": "Affected product configuration nodes. NVD nests these under configuration groups; the groups are represented by groupIndex so each node's own criteria stay together."
          },
          "references": {
            "description": "External references.",
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "url": {
                  "type": "string",
                  "description": "Reference URL."
                },
                "source": {
                  "description": "Who contributed the reference, as the contributor name NVD publishes for it (e.g. \"CVE\", \"CISA-ADP\"). Contributors NVD identifies by email address keep that address (e.g. \"[email protected]\"); an identifier absent from NVD's contributor dictionary passes through as its raw value.",
                  "type": "string"
                },
                "tags": {
                  "description": "Classification tags.",
                  "type": "array",
                  "items": {
                    "type": "string",
                    "description": "One classification tag."
                  }
                }
              },
              "required": [
                "url"
              ],
              "additionalProperties": false,
              "description": "One external reference."
            }
          },
          "cisaKev": {
            "description": "CISA KEV fields. Present only when CVE is in the KEV catalog.",
            "type": "object",
            "properties": {
              "exploitAddDate": {
                "type": "string",
                "description": "Date added to CISA KEV catalog."
              },
              "actionDueDate": {
                "type": "string",
                "description": "Federal agency remediation deadline."
              },
              "requiredAction": {
                "type": "string",
                "description": "Required remediation steps."
              },
              "vulnerabilityName": {
                "type": "string",
                "description": "CISA's vulnerability name."
              }
            },
            "required": [
              "exploitAddDate",
              "actionDueDate",
              "requiredAction",
              "vulnerabilityName"
            ],
            "additionalProperties": false
          }
        },
        "required": [
          "cveId",
          "vulnStatus",
          "published",
          "lastModified",
          "descriptions",
          "cvssScores",
          "weaknesses",
          "configurationNodes"
        ],
        "additionalProperties": false,
        "description": "Full CVE record for one vulnerability affecting the product."
      },
      "description": "Full CVE records for CVEs affecting the specified product."
    },
    "totalCount": {
      "type": "number",
      "description": "Total CVEs matched before pagination."
    },
    "returned": {
      "type": "number",
      "description": "Number of CVE records returned."
    },
    "offset": {
      "type": "number",
      "description": "Page offset used in this query."
    },
    "auditTarget": {
      "type": "string",
      "description": "The CPE name or virtual match string used for this audit."
    },
    "severityMin": {
      "description": "The client-side minimum severity filter applied. Absent when none was set.",
      "type": "string"
    },
    "filteredCount": {
      "description": "CVEs dropped by the severityMin filter from the page NVD returned. Present whenever severityMin is set; 0 means the filter dropped nothing, so a narrow result reflects totalCount and limit instead. This is not totalCount minus returned — CVEs beyond limit were never fetched and so were never evaluated against the filter.",
      "type": "number"
    },
    "notice": {
      "description": "Guidance on the shape of this page. When no CVEs came back it distinguishes a target NVD holds no CVEs for from a severityMin filter that dropped everything on the page, from an offset past the result set, from an empty page NVD returned inside a range it says has matches. On a partial page it names the offset that reaches the next one.",
      "type": "string"
    },
    "error": {
      "description": "Present when the call failed. Absent on success.",
      "type": "object",
      "properties": {
        "code": {
          "type": "integer",
          "minimum": -9007199254740991,
          "maximum": 9007199254740991,
          "description": "JSON-RPC error code for this failure."
        },
        "message": {
          "type": "string",
          "description": "Human-readable description of what went wrong."
        },
        "data": {
          "type": "object",
          "properties": {
            "reason": {
              "type": "string",
              "description": "Machine-readable failure mode. Declared by this tool: `missing_cpe_input`: Neither cpeName nor virtualMatchString was provided. `conflicting_cpe_inputs`: Both cpeName and virtualMatchString were provided simultaneously. `version_range_without_match_string`: versionStart or versionEnd was provided without virtualMatchString. `invalid_cpe_format`: cpeName or virtualMatchString does not start with \"cpe:2.3:\", or NVD rejected it as a malformed CPE parameter — cpeName rejects anything short of a complete CPEv2.3 name, virtualMatchString only genuinely malformed characters. `rate_limited`: NVD returned HTTP 403 indicating the rate limit was exceeded. Other values are possible when a failure originates below the handler.",
              "examples": [
                "missing_cpe_input",
                "conflicting_cpe_inputs",
                "version_range_without_match_string",
                "invalid_cpe_format",
                "rate_limited"
              ]
            },
            "recovery": {
              "description": "Actionable next step for the caller.",
              "type": "object",
              "properties": {
                "hint": {
                  "type": "string"
                }
              },
              "required": [
                "hint"
              ],
              "additionalProperties": {}
            },
            "retryable": {
              "description": "Whether retrying may succeed.",
              "type": "boolean"
            }
          },
          "additionalProperties": {}
        }
      },
      "required": [
        "code",
        "message"
      ],
      "additionalProperties": {}
    }
  },
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false,
  "anyOf": [
    {
      "not": {
        "required": [
          "error"
        ]
      },
      "required": [
        "cves",
        "totalCount",
        "returned",
        "offset",
        "auditTarget"
      ]
    },
    {
      "required": [
        "error"
      ]
    }
  ]
}
🟢nvd_search_cpes(keyword, cpeMatchString, limit, offset)

Search the NVD CPE (Common Platform Enumeration) dictionary by product keyword or partial match string. Returns CPE names, human-readable titles, and deprecation status. Use before nvd_audit_cpe to resolve the correct CPE name for a product — CPE strings are precise identifiers (e.g., cpe:2.3:a:apache:http_server:2.4.51:*:*:*:*:*:*:*) and must match exactly to audit the right product.

输入模式

{
  "type": "object",
  "properties": {
    "keyword": {
      "description": "Product name or vendor keyword (e.g., \"apache http server\", \"openssl\", \"nginx\"). At least one of keyword or cpeMatchString is required.",
      "type": "string"
    },
    "cpeMatchString": {
      "description": "Partial CPEv2.3 pattern (e.g., \"cpe:2.3:a:apache:http_server\"). At least one of keyword or cpeMatchString is required.",
      "type": "string"
    },
    "limit": {
      "default": 20,
      "description": "Maximum number of CPE entries to return (default 20, max 10000).",
      "type": "integer",
      "minimum": 1,
      "maximum": 10000
    },
    "offset": {
      "default": 0,
      "description": "Zero-based page offset for pagination. When totalCount exceeds offset + returned, raise offset to reach the rest — a vendor-level keyword has nothing left to narrow toward.",
      "type": "integer",
      "minimum": 0,
      "maximum": 9007199254740991
    }
  },
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false
}

输出模式

{
  "type": "object",
  "properties": {
    "cpes": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "cpeName": {
            "type": "string",
            "description": "Full CPEv2.3 name (use this as the cpeName in nvd_audit_cpe)."
          },
          "title": {
            "description": "Human-readable product title. Absent when NVD has no English title.",
            "type": "string"
          },
          "deprecated": {
            "type": "boolean",
            "description": "Whether this CPE has been deprecated in the NVD dictionary."
          },
          "deprecatedBy": {
            "description": "CPE names that supersede this deprecated entry.",
            "type": "array",
            "items": {
              "type": "string",
              "description": "Superseding CPE name."
            }
          },
          "lastModified": {
            "description": "ISO 8601 datetime when this CPE was last modified.",
            "type": "string"
          }
        },
        "required": [
          "cpeName",
          "deprecated"
        ],
        "additionalProperties": false,
        "description": "One CPE dictionary entry."
      },
      "description": "Matching CPE dictionary entries."
    },
    "totalCount": {
      "type": "number",
      "description": "Total matching CPE entries before the limit was applied."
    },
    "returned": {
      "type": "number",
      "description": "Number of entries returned in this response."
    },
    "offset": {
      "type": "number",
      "description": "Page offset used in this query."
    },
    "notice": {
      "description": "Guidance when no CPEs matched, the offset ran past the result set, NVD returned an empty page inside a range it says has matches, or entries remain beyond this page.",
      "type": "string"
    },
    "error": {
      "description": "Present when the call failed. Absent on success.",
      "type": "object",
      "properties": {
        "code": {
          "type": "integer",
          "minimum": -9007199254740991,
          "maximum": 9007199254740991,
          "description": "JSON-RPC error code for this failure."
        },
        "message": {
          "type": "string",
          "description": "Human-readable description of what went wrong."
        },
        "data": {
          "type": "object",
          "properties": {
            "reason": {
              "type": "string",
              "description": "Machine-readable failure mode. Declared by this tool: `missing_search_input`: Neither keyword nor cpeMatchString was provided. `invalid_cpe_format`: The cpeMatchString does not start with \"cpe:2.3:\", or NVD rejected it as a malformed CPE parameter. A merely truncated prefix is a legitimate partial match and returns an empty page instead. `rate_limited`: NVD returned HTTP 403 indicating the rate limit was exceeded. Other values are possible when a failure originates below the handler.",
              "examples": [
                "missing_search_input",
                "invalid_cpe_format",
                "rate_limited"
              ]
            },
            "recovery": {
              "description": "Actionable next step for the caller.",
              "type": "object",
              "properties": {
                "hint": {
                  "type": "string"
                }
              },
              "required": [
                "hint"
              ],
              "additionalProperties": {}
            },
            "retryable": {
              "description": "Whether retrying may succeed.",
              "type": "boolean"
            }
          },
          "additionalProperties": {}
        }
      },
      "required": [
        "code",
        "message"
      ],
      "additionalProperties": {}
    }
  },
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false,
  "anyOf": [
    {
      "not": {
        "required": [
          "error"
        ]
      },
      "required": [
        "cpes",
        "totalCount",
        "returned",
        "offset"
      ]
    },
    {
      "required": [
        "error"
      ]
    }
  ]
}
🟢nvd_get_cve_history(cveId, limit, offset, order)

Retrieve the change history for a single CVE — CVSS score revisions, reference additions, status transitions (e.g., "Received" → "Analyzed"), and CPE configuration updates. Use when tracking a CVE's escalation or investigating when a score changed. Events are returned newest-first by default; pass order="oldest" for the CVE's earliest events. For the current record, call nvd_get_cve instead. The NVD history endpoint is significantly slower than other NVD endpoints, especially without an API key — set NVD_API_KEY for reliable operation.

输入模式

{
  "type": "object",
  "properties": {
    "cveId": {
      "type": "string",
      "description": "CVE identifier to retrieve history for (e.g., \"CVE-2021-44228\")."
    },
    "limit": {
      "default": 20,
      "description": "Maximum number of change events to return (default 20, max 2000).",
      "type": "integer",
      "minimum": 1,
      "maximum": 2000
    },
    "offset": {
      "default": 0,
      "description": "Zero-based offset for paginating through change events, counted from whichever end order anchors to: offset 0 is the newest event under the default order=\"newest\", and the oldest event under order=\"oldest\".",
      "type": "integer",
      "minimum": 0,
      "maximum": 9007199254740991
    },
    "order": {
      "default": "newest",
      "description": "Which end of the history to page from. Default \"newest\" returns the most recent events first, which is what escalation and re-score questions need. \"oldest\" returns NVD's native order (the CVE's first events first) and costs one upstream request, or two when the offset overruns the history; \"newest\" costs up to two on any history longer than limit.",
      "type": "string",
      "enum": [
        "oldest",
        "newest"
      ]
    }
  },
  "required": [
    "cveId"
  ],
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false
}

输出模式

{
  "type": "object",
  "properties": {
    "cveId": {
      "type": "string",
      "description": "The CVE ID for which history was retrieved."
    },
    "changes": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "changeDate": {
            "type": "string",
            "description": "ISO 8601 datetime when this change occurred."
          },
          "eventName": {
            "description": "Name of the change event (e.g., \"CVE Modified\", \"Initial Analysis\").",
            "type": "string"
          },
          "details": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "action": {
                  "description": "The action taken (e.g., \"Added\", \"Changed\", \"Removed\").",
                  "type": "string"
                },
                "type": {
                  "description": "The type of data changed (e.g., \"CVSS V3.1\", \"CWE\", \"Reference\").",
                  "type": "string"
                },
                "oldValue": {
                  "description": "The value before the change. Structured upstream values (e.g. \"Affected\", \"SSVC\" details) arrive as a JSON string — parse it to read the fields.",
                  "type": "string"
                },
                "newValue": {
                  "description": "The value after the change. Structured upstream values (e.g. \"Affected\", \"SSVC\" details) arrive as a JSON string — parse it to read the fields.",
                  "type": "string"
                }
              },
              "additionalProperties": false,
              "description": "One field-level change within this event."
            },
            "description": "Individual change detail entries within this event."
          }
        },
        "required": [
          "changeDate",
          "details"
        ],
        "additionalProperties": false,
        "description": "One CVE change event with its field-level details."
      },
      "description": "CVE change events ordered to match the requested order — newest first by default, oldest first when order=\"oldest\"."
    },
    "totalCount": {
      "type": "number",
      "description": "Total change events on record for this CVE."
    },
    "returned": {
      "type": "number",
      "description": "Number of change events returned in this response."
    },
    "offset": {
      "type": "number",
      "description": "Page offset used in this query."
    },
    "order": {
      "type": "string",
      "enum": [
        "oldest",
        "newest"
      ],
      "description": "Which end of the history this page was anchored to."
    },
    "notice": {
      "description": "Guidance on the shape of this page. When no events came back it distinguishes an offset past the end of the history, from an empty page NVD returned inside a range it says has events, from a CVE NVD holds no history for — the last of which covers both a record it has never revised and a CVE ID it does not hold. On a partial page it names the offset that reaches the next one, counted from the same end order anchors to.",
      "type": "string"
    },
    "error": {
      "description": "Present when the call failed. Absent on success.",
      "type": "object",
      "properties": {
        "code": {
          "type": "integer",
          "minimum": -9007199254740991,
          "maximum": 9007199254740991,
          "description": "JSON-RPC error code for this failure."
        },
        "message": {
          "type": "string",
          "description": "Human-readable description of what went wrong."
        },
        "data": {
          "type": "object",
          "properties": {
            "reason": {
              "type": "string",
              "description": "Machine-readable failure mode. Declared by this tool: `invalid_cve_id_format`: The CVE ID fails format validation (NVD returns HTTP 404 for malformed IDs). `rate_limited`: NVD returned HTTP 403 indicating the rate limit was exceeded. Other values are possible when a failure originates below the handler.",
              "examples": [
                "invalid_cve_id_format",
                "rate_limited"
              ]
            },
            "recovery": {
              "description": "Actionable next step for the caller.",
              "type": "object",
              "properties": {
                "hint": {
                  "type": "string"
                }
              },
              "required": [
                "hint"
              ],
              "additionalProperties": {}
            },
            "retryable": {
              "description": "Whether retrying may succeed.",
              "type": "boolean"
            }
          },
          "additionalProperties": {}
        }
      },
      "required": [
        "code",
        "message"
      ],
      "additionalProperties": {}
    }
  },
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false,
  "anyOf": [
    {
      "not": {
        "required": [
          "error"
        ]
      },
      "required": [
        "cveId",
        "changes",
        "totalCount",
        "returned",
        "offset",
        "order"
      ]
    },
    {
      "required": [
        "error"
      ]
    }
  ]
}

推荐提示词

search_research
Search for information about [topic] using nist-nvd-mcp-server
预期工具: nvd_search_cves
find_specific
Find [specific item] using nist-nvd-mcp-server
预期工具: nvd_search_cves
retrieve_data
Get details about [item] from nist-nvd-mcp-server
预期工具: nvd_get_cve
fetch_info
Fetch [information type] using nist-nvd-mcp-server
预期工具: nvd_get_cve
research_workflow
Search for [topic], then get detailed information about the top results using nist-nvd-mcp-server
预期工具: nvd_search_cvesnvd_get_cve

社区

评价此服务器

证据

最近观测

已验证未记录版本5 个工具
已验证未记录版本5 个工具