Cisa Kev MCP server
Use this MCP server to CISA Known Exploited Vulnerabilities catalog search. Tools include search...
0 stars
Reviews
Write oneNobody has reviewed Cisa Kev yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Cisa Kev tools (3)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
catalog_infoGet CISA KEV catalog version and release metadata.
recent_known_exploitedList the most recently added entries in the CISA KEV catalog.
search_known_exploitedSearch CISA's catalog of vulnerabilities known to be exploited in the wild.
Public scan report
scanner v0.1.9 · 2026-09-21 · same rubric, same numbers if you re-run it
- Code scan8 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 44 days ago12/15
- Maintainer identityregistry namespace matches repository owner6/10
Install directly
Runs npx -y cisa-kev-mcp on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add cisa-kev-mcp -- npx -y cisa-kev-mcp
Cisa Kev: common questions
- Is Cisa Kev MCP server safe?
- Yes, by our scan: it is graded A (85/100). Read the Cisa Kev safety report
- How do I install Cisa Kev?
- It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
- Does Cisa Kev need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is Cisa Kev maintained?
- The last commit was 45 days ago (2026-08-08). The latest release is v1.0.1.
- What can I use instead of Cisa Kev?
- Servers from other publishers that do the same job: GitHits MCP server.
Alternatives to Cisa Kev
Same job from other publishers: the closest match first, then the best rated.
GitHitsSearch public open-source code, documentation, metadata, vulnerabilities, changelogs, and examples.not reviewedEstablishedA