Skip to content
ToolCargo

OSV Vulnerability Lookup

Live

Check package versions against public vulnerability advisories.

Look up public OSV advisories for a package version or an advisory ID. Review source-linked descriptions, aliases, severity vectors and affected version ranges across seven package ecosystems.

Connect / 2 tools

Server URL

streamable http
https://toolcargo.com/mcp/osv

Claude Code

terminal
claude mcp add --transport http --scope user toolcargo-osv https://toolcargo.com/mcp/osv \
  --header "Authorization: Bearer YOUR_API_KEY"

Create a key in your dashboard. Other clients: setup guides.

What it helps you do

  • Public advisory matches for a named package version
  • Source-linked details and affected version ranges
  • Clear limits, withdrawn status and pagination indicators

Built for: Developers and agents reviewing known dependency advisories before deciding what to investigate.

Example requests

Investigate a dependency advisory

“Query OSV for npm lodash version 4.17.20, then look up a matching advisory and summarize its affected ranges with source links and caveats.”

Known OSV advisory metadata for an agent to review against the actual dependency graph.

Explore useful agent workflows ↗

Tools

ToolWhat it doesAccess
osv_query_package
Check a package version against OSV
Query public OSV advisories for one package and version in npm, PyPI, Go, crates.io, Maven, NuGet or RubyGems. Returns up to 20 bounded records from one upstream page with source links, ranges and truncation/pagination indicators. No matches is not a safety verdict. One shared-plan call.Read-only
osv_get_vulnerability
Look up an OSV advisory
Retrieve one public OSV advisory by case-sensitive ID with bounded details, aliases, severity vectors, source references and affected ranges/versions. Explicitly identifies withdrawn records and truncated fields. Does not assess exploitability or install software. One shared-plan call.Read-only

Requirements

  • • A ToolCargo account with Site Audit activated (free). No OSV account or external API key.

Limitations

  • • Known public advisories only. Missing results do not establish safety; version matching and source data can be incomplete or outdated.
  • • One package/version and one upstream page per query, at most 20 projected records. nextPageToken skips to the next upstream page, not locally omitted records.
  • • Each record: up to 20 aliases/references, 10 severity entries/affected packages/ranges, 30 events per range and 50 explicit versions per affected entry. Details limited to 6,000 characters; truncation identified.
  • • No dependency graph scan, installation, exploitability assessment or security verdict. Advisory text and reference URLs are untrusted source data.

Supported clients

“Tested” means we connected that client to this endpoint and ran a tool call ourselves. Recorded client-specific tests currently cover Site Audit. Other connectors use the documented setup until tested in that client.

Claude CodeAPI key headerDocumented, not yet testedThis endpoint has not yet been tested in this client. See the setup guide.
Claude (claude.ai)OAuth sign-inDocumented, not yet testedThis endpoint has not yet been tested in this client. See the setup guide.
CursorAPI key headerDocumented, not yet testedThis endpoint has not yet been tested in this client. See the setup guide.
VS Code (Copilot agent mode)API key headerDocumented, not yet testedThis endpoint has not yet been tested in this client. See the setup guide.
ChatGPT (developer mode)OAuth sign-inDocumented, not yet testedThis endpoint has not yet been tested in this client. See the setup guide.
MCP InspectorAPI key headerDocumented, not yet testedThis endpoint has not yet been tested in this client. See the setup guide.

Practical workflows

Pricing

Included with Site Audit. Each successful package query or advisory lookup is one shared-plan call.

Free

$0

Try hosted tools with a shared monthly allowance.

50 shared calls/month

Pro

$12/mo

Proposed larger shared allowance; see checkout status on the pricing page.

2,000 shared calls/month

Proposed test price. See the pricing page for checkout status.

Full pricing and billing details