Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Transports: stdio vs HTTP
  • State of MCP (stats)
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI β†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE β†— (opens in a new tab)
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ”’ Security
  3. Circl Vulnerability Lookup
C
Health: Not checked yetWe have not completed a health check for this listing yet.No health check has run yet.

Circl Vulnerability Lookup

User RatingsBe the first to rate and review this MCP server! Enrichment pendingWe haven’t run our AI enrichment pass on this listing yet, so the overview, use cases, and FAQ below may be sparse or missing. We work through the catalog over time β€” check back soon.
View RepositoryVisit Website

CIRCL Vulnerability-Lookup β€” aggregated vulnerability records

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

One-click editor setup isn’t available for this listing yet β€” we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.

Manual Client & Custom JSON ConfigExpand JSON β–Ύ
No confirmed setup config for this listing yet. We only publish a config block when the install details come from the project itself β€” its README, its docs, or a verified owner. We haven’t found those for Circl Vulnerability Lookup, and we’d rather show nothing than a guess you’d paste into your client. Follow the project’s own setup instructions for the current steps.
Install Directory Badge Claim listing AlternativesπŸ”’ More in Security

Documentation Overview

@pipeworx/circl-vulnerability-lookup

Vulnerability records from CIRCL's Vulnerability-Lookup service, which resolves one id against several upstream feeds at once β€” MITRE CVE, NVD, GitHub Security Advisories, PySec and vendor CSAF advisories.

Part of Pipeworx β€” an MCP gateway connecting AI agents to 1683+ live data sources.

Tools

  • circl_vuln(id, include_raw?) β€” one vulnerability by id. Accepts CVE-, GHSA-, PYSEC- and vendor advisory ids alike. Returns a normalised summary (title, description, CVSS score/vector, affected products, references, dates) plus the untouched upstream record.
  • circl_vuln_search(vendor, product, limit?) β€” every vulnerability recorded against a CPE vendor/product pair, newest first, tagged with the feed each record came from.
  • circl_vuln_recent(limit?) β€” the most recently published or updated records across every aggregated feed.

Auth

Keyless.

Data sources

  • https://vulnerability.circl.lu/api/vulnerability/{id} β€” one record by id.
  • https://vulnerability.circl.lu/api/search/{vendor}/{product} β€” search.
  • https://vulnerability.circl.lu/api/last/{n} β€” recent records.

Operated by CIRCL (Computer Incident Response Center Luxembourg).

Traps

  • An unknown id answers {} with HTTP 200. That is a silent zero β€” parsed naively it reads as a successful empty record. circl_vuln throws a named miss instead.
  • The real paths are not the ones the names suggest. Search is /api/search/{vendor}/{product} and the recent feed is /api/last/{n}. /api/vulnerability/search/... and /api/vulnerability/last are both 404.
  • Records arrive in three different schemas, and one /api/last response mixes all three:
    • CVE JSON 5.x β€” cveMetadata + containers.cna
    • OSV β€” id / details / affected / severity
    • CSAF β€” document / product_tree / vulnerabilities summarize() normalises the shared fields across all three; raw keeps the original. Do not assume containers.cna exists.
  • CVSS lives under a version-specific key (cvssV3_1, cvssV4_0, …) inside containers.cna.metrics[], so the code scans the metric objects rather than reaching for a fixed path. OSV records carry only a vector string in severity[].score, with no numeric base score.
  • Vendor/product are matched against CPE strings, not marketing names β€” use microsoft/windows_10, not Microsoft Windows 10.
  • CIRCL rate-limits by source IP, and publishes the limits at https://vulnerability.circl.lu/.well-known/api-policy.json: 20 requests per minute anonymously, 40 with an X-API-KEY. It does send Retry-After (observed: 59) plus X-RateLimit-Limit/-Remaining/-Reset, and the 429 error here quotes it. This pack is keyless and stays inside the anonymous bucket β€” one tool call is one upstream request. If we ever need the higher tier, it is a header, not a rebuild.
  • The 429 is per backend worker, not global. Measured 2026-09-17: three consecutive anonymous requests from one IP reported x-ratelimit-remaining of 0, then 19, then 3, and one URL kept 429-ing while the next id answered 200 instantly. So a 429 here frequently says nothing about your actual usage β€” circlJson() retries up to 3 times before surfacing it. Do not read a single 429 as "we are being throttled".

Related packs

nvd (NVD directly, platform-keyed) and osv (OSV.dev, open-source package advisories) cover single upstreams. This pack is the cross-feed id resolver: use it when you have an id and do not know which body published it.

Quick Start

Add to your MCP client (Claude Desktop, Cursor, Windsurf, etc.):

config.json
{
  "mcpServers": {
    "circl-vulnerability-lookup": {
      "url": "https://gateway.pipeworx.io/circl-vulnerability-lookup/mcp"
    }
  }
}

What this endpoint actually serves

tools/list at https://gateway.pipeworx.io/circl-vulnerability-lookup/mcp returns the tools in the table above plus the shared Pipeworx meta-tools β€” ask_pipeworx, discover_tools, search_within, remember/recall and the rest of the gateway-wide set. So the tool count you see is larger than this table: a single-pack endpoint currently lists roughly 30 shared tools alongside the pack's own. The connection's initialize response states its exact scope, and is the authoritative answer for a given day.

This is deliberate, not multiplexing by accident. The meta-tools are what let a scoped connection answer a question this pack does not cover β€” via ask_pipeworx, which routes across the whole catalog β€” without you adding a second MCP server. There is currently no way to mount a pack endpoint without them; if the extra schemas cost you more context than the routing is worth, connect to the full gateway once rather than to several pack endpoints.

Or connect to the full Pipeworx gateway to get every pack's tools listed directly, instead of just this one's:

config.json
{
  "mcpServers": {
    "pipeworx": {
      "url": "https://gateway.pipeworx.io/mcp"
    }
  }
}

Both URLs reach the same gateway and the same 1683+ data sources. The only difference is which pack's tools are listed directly; ask_pipeworx reaches all of them from either one.

No MCP client? Call it over HTTP

Terminal
curl -X POST https://gateway.pipeworx.io/v1/tools/circl_vuln \
  -H 'Content-Type: application/json' \
  -d '{"id":"CVE-2014-0160","include_raw":false}'

No account needed for the first calls. Inspect any tool: GET https://gateway.pipeworx.io/v1/tools/circl_vuln. Find one: POST https://gateway.pipeworx.io/v1/tools/search_packs with {"query":"..."}.

Standalone (no gateway account)

This package also runs as a local stdio MCP server β€” no Pipeworx account, no gateway round-trip:

config.json
{
  "mcpServers": {
    "circl-vulnerability-lookup": {
      "command": "npx",
      "args": ["-y", "@pipeworx/mcp-circl-vulnerability-lookup"]
    }
  }
}

Or run it directly to confirm it starts:

Terminal
npx -y @pipeworx/mcp-circl-vulnerability-lookup

It speaks MCP over stdin/stdout and answers initialize/tools/list/tools/call for only this pack's tools β€” none of the shared meta-tools the gateway connection above adds. Same source, same tools, no ask_pipeworx routing.

Using with ask_pipeworx

Instead of calling tools directly, you can ask questions in plain English β€” this works on the pack endpoint above as well as on the full gateway:

Code
ask_pipeworx({ question: "your question about Circl Vulnerability Lookup data" })

The gateway picks the right tool and fills the arguments automatically.

More

  • Docs and guides
  • pipeworx.io

License

MIT

Read the full README β†’View source on GitHub β†’

Related MCP Servers

View all in Security View all alternatives
  • M
    MCP Fortress

    Security scanner for MCP servers with vulnerability detection and prompt injection analysis.

    πŸ”’ Security1 views
    Compare vs MCP Fortress β†’
  • I
    Ida Pro MCP

    MCP server for IDA Pro, allowing you to perform binary analysis with AI assistants. This plugin implement decompilation, disassembly and allows you to generate malware analysis reports automatically.

    πŸ”’ Security4 views
    Compare vs Ida Pro MCP β†’
  • U
    Ui Ux Suite

    UI/UX design-audit MCP server: scores a project on 12 dimensions vs WCAG 2.2 + APCA.

    πŸ”’ Security1 views
    Compare vs Ui Ux Suite β†’
  • A
    Aikido MCP

    Security analysis for Aiken smart contracts on Cardano. 75 vulnerability detectors.

    πŸ”’ Security1 views
    Compare vs Aikido MCP β†’

Reviews

No reviews yet β€” be the first to share how this listing worked for you.

Frequently Asked Questions about Circl Vulnerability Lookup

We don't have a confirmed install command for Circl Vulnerability Lookup yet, so we don't publish a generated one β€” a guessed package name would point at the wrong package or none at all. Follow the project's own README or setup instructions (https://github.com/pipeworx-io/mcp-circl-vulnerability-lookup) for the current steps.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewCircl Vulnerability Lookup AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/circl-vulnerability-lookup?style=directory)](https://allmcps.com/mcp/circl-vulnerability-lookup)
HTML Embed
<a href="https://allmcps.com/mcp/circl-vulnerability-lookup"><img src="https://allmcps.com/api/badge/circl-vulnerability-lookup?style=directory" alt="Circl Vulnerability Lookup on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ”’Security
More technical detailsExpand β–Ύ
Last updatedSep 28, 2026
Views0
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
25Quality signal: Emerging Β· 25/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership8/20
Documentation & tools10/30
Adoption & activity1/15
Community engagement0/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

β˜… Featured
M

Moxie Docs MCP

MCP & Agent Skills for Automated Documentation, and codebase conventions + context

Explore Server β†’

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge β€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it β€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ”’ Security β†’Best MCP servers for Security β†’Alternatives to Circl Vulnerability Lookup β†’Install in Claude DesktopInstall in CursorInstall in VS CodeSetup guides for all 13 MCP clients