echelongraph/echelongraph-mcp
by Various
MCP server for CVE intelligence: 16 read-only tools for CVE records, CISA KEV, EPSS history, exploits, fix guidance as sources state it, version, SBOM and lockfile checks, vendor a
MCP
echelongraph/echelongraph-mcp
Added 8 Oct 2026
Overview
MCP server for CVE intelligence. It provides 16 read-only tools for accessing CVE records, CISA KEV, EPSS history, exploits, fix guidance, version checks, SBOM and lockfile checks, vendor advisories, and per-CVE exposure from Shodan data. Free and keyless.
Best for
Best for
Developers building MCP-based security workflows who want a keyless CVE data source
Use cases
- Look up CVE details and CISA KEV status
- Check exploit availability and EPSS scores for a CVE
- Scan SBOM or lockfiles for known vulnerable versions
How to use
Install
claude mcp add --transport stdio echelongraph -- npx -y echelongraph-mcp Tools exposed
cve_summarysearch_cvesget_cvecve_exposureexposure_radarkev_recentepss_historycheck_affectedcheck_sbomscan_manifestcve_intelcve_remediationget_cwevendor_advisories_for_cveget_vendor_advisorysearch_vendor_advisoriesexposure_statenot_assessedmeasured_zero
Tested with
Claude Desktop, Claude Code, Cursor, Windsurf, Cline, VS Code
Example client config
{\n "preferences": {\n "…": "the settings already in your file stay as they are"\n },\n "mcpServers": {\n "echelongraph": {\n "command": "npx",\n "args": ["-y", "echelongraph-mcp"]\n }\n }\n } Notes
MCP server for CVE intelligence. It provides 16 read-only tools for accessing CVE records, CISA KEV, EPSS history, exploits, fix guidance, version checks, SBOM and lockfile checks, vendor advisories, and per-CVE exposure from Shodan data. Free and keyless.
2 stars on GitHub. Last updated 2026-10-06. Licensed MIT.
Use cases
- Look up CVE details and CISA KEV status
- Check exploit availability and EPSS scores for a CVE
- Scan SBOM or lockfiles for known vulnerable versions
Pros
- No API key or payment required
- Covers multiple CVE intelligence sources in one tool
- Read-only tools reduce risk of accidental changes
Cons
- Low community adoption (2 GitHub stars)
- Limited evidence of ongoing maintenance or support
- Requires a JavaScript/Node.js environment to run
Indexed from awesome-mcp-servers-punkpeye and enriched against its public facts.
Pros
- No API key or payment required
- Covers multiple CVE intelligence sources in one tool
- Read-only tools reduce risk of accidental changes
Cons
- Low community adoption (2 GitHub stars)
- Limited evidence of ongoing maintenance or support
- Requires a JavaScript/Node.js environment to run
Pairs with
Other entries in the index that connect to this one. Click through to see the chain.
Get the free Developer’s Field Guide
A 27-page field guide to the AI coding workflow with Claude. Claude Code, MCP servers, the prompt patterns that work, and what to delegate. Free.
Enter your work email. We send it straight over, plus a few short notes worth knowing. Unsubscribe any time.
