CVE MCP Server v0.2.0
A major feature release. Additive — all existing tools remain registered; the new triage_cve orchestrator is the recommended entry point.
⭐ Orchestration
triage_cve— one tool call fans out NVD + EPSS + CISA KEV (+ public PoC discovery) concurrently, computes the composite risk score, and returns a clean report.depth=quick/standard/deep;deepalso emits an SSVC v2 gated decision (CISA Deployer model →Act/Attend/Track*/Track).- Transparent VulnCheck NVD++ fallback used automatically when NIST NVD is unreachable or throttled.
🎯 Scoring
- CISA KEV hard override — a KEV-listed CVE is always CRITICAL (score clamped ≥ 76), regardless of CVSS/EPSS.
scoring_versionstamped intotriage_cve,calculate_risk_score, andhealth_check.- CVSS reframed as a severity signal (not exploitation-likelihood), per Allodi & Massacci 2014.
🔌 New data sources
- VulnCheck NVD++ (NVD-schema fallback), CIRCL hashlookup (known-good allowlist), HIBP Pwned Passwords range API (keyless k-anonymity).
🧩 MCP enhancements
- Resources:
kev://catalog,epss://scores/{cve_id},manifest://tool-hash(SHA-256 over the registered tool surface). - Prompts:
patch_decision,compare_and_prioritize,dependency_triage. - Streamable-HTTP transport via
MCP_TRANSPORT=http(stdio remains the default). - Expanded
health_check(scoring version, manifest hash, configured-key status).
🔐 Security hardening
- Server never registers a sampling handler / never issues
sampling/createMessage(Unit 42 MCP-sampling attack vector). - SSRF defense: scheme allowlist + resolve-then-validate (rejects private/reserved IPs).
- Secrets centralized as Pydantic
SecretStr.
🏗️ Infrastructure
- Multi-stage non-root Dockerfile +
.dockerignore. - SQLite WAL pragmas for concurrent reads; null-object rate limiter; fixed-interval deterministic retry; async fan-out helper; static Admiralty source-trust table.
Verified: ruff clean, 30/30 tests passing.
Full Changelog: v0.1.0...v0.2.0
What's Changed
New Contributors
Full Changelog: v0.1.0...v0.2.0