Most vulnerability lookups stop at this package is affected. The two CVE tools here close the loop — the affected range and the fixed range, which is the number that ends the conversation.
A lightweight client for the OSV vulnerability database. Give it a package and it returns the CVE identifiers against it, optionally narrowed to one version; give it a CVE and it returns the affected versions and the versions that fix it.
- Every CVE for a package, with an optional version to narrow the scope
- The affected version list for a CVE
- The versions that fix a CVE — the number you actually have to upgrade to
- The ecosystems OSV covers, each mapped to its language or operating system
- PyPI assumed by default, with any other ecosystem named per call
A recent Python and uv. OSV's data is public, so no account and no key. Install through Smithery, or run from a local clone.
One command — npx -y @smithery/cli install @EdenYavin/OSV-MCP --client claude
