osv-mcp logo

osv-mcpAn MCP server for OSV

(0)
Daniel NikulshynReviewed by Daniel Nikulshyn·Updated July 2026

Overview

The osv-mcp project is an MCP (Model Context Protocol) server that provides access to the OSV (Open Source Vulnerabilities) database. It allows LLM-powered applications to query the OSV database for vulnerability information using an SSE-based MCP server. The server supports querying vulnerabilities for specific package versions or commits, batch querying vulnerabilities for multiple packages or commits, and getting detailed information about specific vulnerabilities by ID.

Key features

  • Query vulnerabilities for a specific package version or commit
  • Batch query vulnerabilities for multiple packages or commits
  • Get detailed information about a specific vulnerability by ID
  • SSE-based MCP server
  • Support for multiple transport modes (sse, streamable-http)

Pricing

Model
Free
Category
MCP Servers
Rating
No reviews yet

Use cases

Vulnerability Management

Use the osv-mcp server to query vulnerabilities for specific package versions or commits, and get detailed information about specific vulnerabilities by ID.

Batch Vulnerability Assessment

Use the osv-mcp server to batch query vulnerabilities for multiple packages or commits, allowing for efficient assessment of vulnerabilities in large-scale applications.

Pros & Cons

Pros

  • Provides secure, containerized deployment of MCP servers using ToolHive
  • Supports querying vulnerabilities for specific package versions or commits
  • Allows batch querying vulnerabilities for multiple packages or commits
  • Provides detailed information about specific vulnerabilities by ID

Cons

  • Requires Go 1.21 or later to build from source
  • Requires ToolHive for recommended deployment

Reviews

Sign in to leave a review.

No reviews yet. Be the first!

Q&A

How to run the server?

The server can be run using ToolHive for secure containerized deployment or from source using environment variables for configuration.

Asked by Lior Ben-David · Jan 9, 2026

What are the system requirements?

The osv-mcp project requires Go 1.21 or later to build from source and ToolHive for recommended deployment.

Asked by Quyen Tran · Dec 20, 2025

What are the key features?

Key features include querying vulnerabilities for specific packages or commits, batch querying, and detailed information about specific vulnerabilities by ID.

Asked by Olga Ivanova · Dec 6, 2025

What is osv-mcp?

osv-mcp is an MCP server that provides access to the OSV database, allowing LLM-powered applications to query vulnerability information.

Asked by Sofia Lindqvist · Dec 5, 2025

Ask a question

MCP Servers alternatives