Enterprise DNA Enterprise DNA
M MCP Servers Developer low

echelongraph/echelongraph-mcp

by Various

MCP server for CVE intelligence: 16 read-only tools for CVE records, CISA KEV, EPSS history, exploits, fix guidance as sources state it, version, SBOM and lockfile checks, vendor a

MCP

echelongraph/echelongraph-mcp

Added 8 Oct 2026

#cisa-kev #cve #cybersecurity #epss #mcp #mcp-server #model-context-protocol #sbom

Overview

MCP server for CVE intelligence. It provides 16 read-only tools for accessing CVE records, CISA KEV, EPSS history, exploits, fix guidance, version checks, SBOM and lockfile checks, vendor advisories, and per-CVE exposure from Shodan data. Free and keyless.

Best for

Best for
Developers building MCP-based security workflows who want a keyless CVE data source

Use cases

  • Look up CVE details and CISA KEV status
  • Check exploit availability and EPSS scores for a CVE
  • Scan SBOM or lockfiles for known vulnerable versions

How to use

Install

claude mcp add --transport stdio echelongraph -- npx -y echelongraph-mcp

Tools exposed

  • cve_summary
  • search_cves
  • get_cve
  • cve_exposure
  • exposure_radar
  • kev_recent
  • epss_history
  • check_affected
  • check_sbom
  • scan_manifest
  • cve_intel
  • cve_remediation
  • get_cwe
  • vendor_advisories_for_cve
  • get_vendor_advisory
  • search_vendor_advisories
  • exposure_state
  • not_assessed
  • measured_zero

Tested with

Claude Desktop, Claude Code, Cursor, Windsurf, Cline, VS Code

Example client config

{\n     "preferences": {\n       "…": "the settings already in your file stay as they are"\n     },\n     "mcpServers": {\n       "echelongraph": {\n         "command": "npx",\n         "args": ["-y", "echelongraph-mcp"]\n       }\n     }\n   }

Notes

MCP server for CVE intelligence. It provides 16 read-only tools for accessing CVE records, CISA KEV, EPSS history, exploits, fix guidance, version checks, SBOM and lockfile checks, vendor advisories, and per-CVE exposure from Shodan data. Free and keyless.

2 stars on GitHub. Last updated 2026-10-06. Licensed MIT.

Use cases

  • Look up CVE details and CISA KEV status
  • Check exploit availability and EPSS scores for a CVE
  • Scan SBOM or lockfiles for known vulnerable versions

Pros

  • No API key or payment required
  • Covers multiple CVE intelligence sources in one tool
  • Read-only tools reduce risk of accidental changes

Cons

  • Low community adoption (2 GitHub stars)
  • Limited evidence of ongoing maintenance or support
  • Requires a JavaScript/Node.js environment to run

Indexed from awesome-mcp-servers-punkpeye and enriched against its public facts.

Pros

  • No API key or payment required
  • Covers multiple CVE intelligence sources in one tool
  • Read-only tools reduce risk of accidental changes

Cons

  • Low community adoption (2 GitHub stars)
  • Limited evidence of ongoing maintenance or support
  • Requires a JavaScript/Node.js environment to run
Free 27-page guide

Get the free Developer’s Field Guide

A 27-page field guide to the AI coding workflow with Claude. Claude Code, MCP servers, the prompt patterns that work, and what to delegate. Free.

Enter your work email. We send it straight over, plus a few short notes worth knowing. Unsubscribe any time.

No spam. Unsubscribe any time.

Running a business, not writing the code? See the MCP servers picked for operators, and get your first one wired up with us.

Operator picks