The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Osv Dev listing page.
OSV.dev MCP — Google's open-source vulnerability database.
Part of Pipeworx — an MCP gateway connecting AI agents to 673+ live data sources.
| Tool | Description |
|---|---|
vulnerabilities | Query vulnerabilities by package (+ optional version) or git commit. |
query_batch | Batch query (≤1000 queries). Pass an array of {package: {name, ecosystem}, version?} or {commit}. |
get | Full vulnerability record by id (CVE-…, GHSA-…, OSV-…). |
Add to your MCP client (Claude Desktop, Cursor, Windsurf, etc.):
Or connect to the full Pipeworx gateway for access to all 673+ data sources:
Instead of calling tools directly, you can ask questions in plain English:
The gateway picks the right tool and fills the arguments automatically.
MIT