Enterprise DNA
M MCP Servers Developer low

toan203/osv-ui

by Various

A beautiful, zero-config visual CVE dashboard for npm & Python. One command: npx osv-ui. 100% Local & Secure.

T

MCP

toan203/osv-ui

Added 1 June 2026

#audit-source #cve #cve-mcp #cve-scanner-dashboard #cve-scanner-ui #cve-scanning #cve-search #cybersecurity

Overview

A zero-config local dashboard that scans npm and Python dependencies for known CVEs using the OSV API. Run one command (npx osv-ui) to get a visual report of vulnerabilities without sending data to external servers.

Best for

Best for
Developers who want a quick, private, visual CVE scan for npm or Python projects without adding a CI step.

Use cases

  • Audit npm dependencies for CVEs before a release
  • Check Python package vulnerabilities in a local project
  • Quickly visualize security issues without configuring a CI pipeline

Notes

A zero-config local dashboard that scans npm and Python dependencies for known CVEs using the OSV API. Run one command (npx osv-ui) to get a visual report of vulnerabilities without sending data to external servers.

4 stars on GitHub. Last updated 2026-03-24. Licensed MIT.

Use cases

  • Audit npm dependencies for CVEs before a release
  • Check Python package vulnerabilities in a local project
  • Quickly visualize security issues without configuring a CI pipeline

Pros

  • Zero setup: one command runs the full scan
  • 100% local processing keeps dependency data private
  • Clean visual dashboard for browsing vulnerabilities

Cons

  • Limited to npm and Python ecosystems only
  • Relies on the OSV API which may have rate limits or latency
  • No automated remediation or fix suggestions

Indexed from awesome-mcp-servers-punkpeye and enriched against its public facts.

Pros

  • Zero setup: one command runs the full scan
  • 100% local processing keeps dependency data private
  • Clean visual dashboard for browsing vulnerabilities

Cons

  • Limited to npm and Python ecosystems only
  • Relies on the OSV API which may have rate limits or latency
  • No automated remediation or fix suggestions