Sign inSign up

hackerdogs/cvemap-mcp

By hackerdogs

•Updated 3 months ago

Cvemap MCP Server

Image
0

582

hackerdogs/cvemap-mcp repository overview

Hackerdogs
hackerdogs ⁠

⁠Cvemap MCP Server

MCP server wrapper for Cvemap⁠ — CVE and vulnerability search, filtering, and analysis.

⁠What is Cvemap?

Cvemap is a CLI tool by ProjectDiscovery that provides a structured interface for browsing and exploring CVEs. It supports searching and filtering by product, vendor, severity, CVSS score, and more, making it easy to stay on top of vulnerability data.

⁠Prerequisites

Cvemap works without an API key but is rate-limited without one. A free ProjectDiscovery Cloud Platform (PDCP) API key is recommended.

Get your free key at: cloud.projectdiscovery.io⁠

export PDCP_API_KEY=your_api_key_here

Summary. MCP server wrapper for Cvemap⁠ — CVE and vulnerability search, filtering, and analysis.

Tools:

  • search_cves — Search CVEs with filters (product, vendor, severity, CVSS score).
  • get_cve_details — Get details for specific CVE(s).
  • list_filters — List available CVE search filter fields. No parameters.
  • analyze_cves — Aggregate and analyze CVEs by a field (severity, vendor, product, year).

⁠Tools Reference

⁠search_cves

Search CVEs with filters (product, vendor, severity, CVSS score).

ParameterTypeRequiredDefaultDescription
querystringNo—Free-text search query
productstringNo—Filter by product name (e.g. "chrome")
vendorstringNo—Filter by vendor (e.g. "microsoft")
severitystringNo—Filter: "low", "medium", "high", or "critical"
cvss_scorestringNo—CVSS threshold (e.g. ">=7.0")
limitintegerNo25Max results to return
detailedbooleanNofalseInclude detailed CVE information
Example response
[{"cve_id": "CVE-2024-1234", "severity": "high", "cvss_score": 8.1, "product": "chrome", "vendor": "google"}]
⁠get_cve_details

Get details for specific CVE(s).

ParameterTypeRequiredDefaultDescription
cve_idsstringYes—Comma-separated CVE IDs (e.g. "CVE-2024-1234,CVE-2024-5678")
⁠list_filters

List available CVE search filter fields. No parameters.

⁠analyze_cves

Aggregate and analyze CVEs by a field (severity, vendor, product, year).

ParameterTypeRequiredDefaultDescription
fieldstringYes—Field to aggregate by (e.g. "severity", "vendor")
querystringNo—Optional search query to narrow the CVE set

⁠Example Prompts

Here are example prompts you can use with Claude (or any MCP client) when this tool is connected:

  • "Find all critical CVEs affecting Apache HTTP Server."
  • "Show me the details for CVE-2024-3094 (the xz backdoor vulnerability)."
  • "Search for high and critical vulnerabilities in Microsoft Exchange with a CVSS score above 8.0."
  • "What are the latest CVEs for Google Chrome?"
  • "Analyze the severity distribution of CVEs for the vendor 'mozilla'."
  • "List all CVEs for the product 'openssh' that have a CVSS score >= 7.0."

⁠Deploy

docker-compose up -d
⁠Docker Run (stdio mode)
docker run -i --rm -e PDCP_API_KEY=your_key hackerdogs/cvemap-mcp:latest
⁠Docker Run (HTTP streamable mode)
docker run -d -p 8106:8106 \
  -e PDCP_API_KEY=your_key \
  -e MCP_TRANSPORT=streamable-http \
  -e MCP_PORT=8106 \
  hackerdogs/cvemap-mcp:latest

⁠MCP Client Configuration

⁠Stdio mode (default)

Add to your Claude Desktop or Cursor MCP config:

{
  "mcpServers": {
    "cvemap-mcp": {
      "command": "docker",
      "args": [
        "run", "-i", "--rm",
        "-e", "PDCP_API_KEY",
        "-e", "MCP_TRANSPORT",
        "hackerdogs/cvemap-mcp:latest"
      ],
      "env": {
        "PDCP_API_KEY": "<your-projectdiscovery-api-key>",
        "MCP_TRANSPORT": "stdio"
      }
    }
  }
}
⁠HTTP mode (streamable-http)

First, start the server using Docker Compose or docker run with HTTP mode (see Deploy⁠ above) — API keys are passed as environment variables at container start time. Then point your MCP client at the running server:

{
  "mcpServers": {
    "cvemap-mcp": {
      "url": "http://localhost:8106/mcp"
    }
  }
}

When to use HTTP mode: HTTP mode is ideal for shared/remote deployments, multi-user setups, and Hackerdogs⁠ scheduled prompts. The server runs as a long-lived process and accepts connections from multiple MCP clients concurrently.

⁠Environment Variables

VariableDefaultDescription
PDCP_API_KEY—ProjectDiscovery API key (optional but recommended — rate-limited without it)
MCP_TRANSPORTstdioTransport mode: stdio or streamable-http
MCP_PORT8106Port for streamable-http transport
CVEMAP_BINcvemapPath to cvemap binary

⁠Installing in Hackerdogs

The fastest way to get started is through Hackerdogs⁠:

  1. Log in to your Hackerdogs account.
  2. Go to the Tools Catalog.
  3. Search for the tool by name (e.g. "nuclei", "naabu", "julius").
  4. Expand the tool card and click Install — you're ready to go.

Give it a couple of minutes to go live. Then start querying by asking Hackerdogs to use the tool explicitly (e.g. "Use naabu to scan example.com"). If you don't specify, Hackerdogs will automatically choose the best tool for the job — it may choose this one on its own.

  1. Vendor API key required? Add your key in the config environment variable field before clicking Install. Your key will be encrypted at rest.
  2. Enable / Disable the tool anytime from the Enabled Tools page.
  3. Need to update a key or parameter? Go to My Tools → toggle Show Decrypted Values → edit → Save.

Want to contribute or chat with the team? Join our Discord⁠.

⁠Build

docker build -t hackerdogs/cvemap-mcp:latest .

⁠Testing

⁠Automated tests
./test.sh
⁠Test directly with Docker

1. Start the server in HTTP mode:

docker run -d --rm --name cvemap-test -p 8106:8106 \
  -e MCP_TRANSPORT=streamable-http \
  -e PDCP_API_KEY=your_key \
  hackerdogs/cvemap-mcp:latest

2. Initialize the MCP session:

SESSION_ID=$(curl -s -D - -X POST http://localhost:8106/mcp \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2024-11-05","capabilities":{},"clientInfo":{"name":"test","version":"0.1"}}}' \
  2>&1 | grep -i mcp-session-id | awk '{print $2}' | tr -d '\r\n')

curl -s -X POST http://localhost:8106/mcp \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -H "mcp-session-id: $SESSION_ID" \
  -d '{"jsonrpc":"2.0","method":"notifications/initialized"}'

3. Call a tool:

curl -s -X POST http://localhost:8106/mcp \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -H "mcp-session-id: $SESSION_ID" \
  -d '{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"search_cves","arguments":{"product":"chrome","severity":"critical","limit":5}}}'

4. Clean up:

docker stop cvemap-test

⁠Running the tool directly (bypassing MCP)

You can run the cvemap CLI in the same container by overriding the entrypoint to query CVE data without starting the MCP server.

Search CVE:

docker run -i --rm --entrypoint cvemap hackerdogs/cvemap-mcp:latest -cve CVE-2024-1234

Show help:

docker run -i --rm --entrypoint cvemap hackerdogs/cvemap-mcp:latest -h

Tag summary

Content type

Image

Digest

sha256:24eed3b15…

Size

88.9 MB

Last updated

3 months ago

docker pull hackerdogs/cvemap-mcp