OSV Vulnerability Lookup
LiveCheck package versions against public vulnerability advisories.
Look up public OSV advisories for a package version or an advisory ID. Review source-linked descriptions, aliases, severity vectors and affected version ranges across seven package ecosystems.
Connect / 2 tools
Server URL
https://toolcargo.com/mcp/osvClaude Code
claude mcp add --transport http --scope user toolcargo-osv https://toolcargo.com/mcp/osv \
--header "Authorization: Bearer YOUR_API_KEY"Create a key in your dashboard. Other clients: setup guides.
What it helps you do
- Public advisory matches for a named package version
- Source-linked details and affected version ranges
- Clear limits, withdrawn status and pagination indicators
Built for: Developers and agents reviewing known dependency advisories before deciding what to investigate.
Example requests
Investigate a dependency advisory
“Query OSV for npm lodash version 4.17.20, then look up a matching advisory and summarize its affected ranges with source links and caveats.”
Known OSV advisory metadata for an agent to review against the actual dependency graph.
Tools
| Tool | What it does | Access |
|---|---|---|
osv_query_packageCheck a package version against OSV | Query public OSV advisories for one package and version in npm, PyPI, Go, crates.io, Maven, NuGet or RubyGems. Returns up to 20 bounded records from one upstream page with source links, ranges and truncation/pagination indicators. No matches is not a safety verdict. One shared-plan call. | Read-only |
osv_get_vulnerabilityLook up an OSV advisory | Retrieve one public OSV advisory by case-sensitive ID with bounded details, aliases, severity vectors, source references and affected ranges/versions. Explicitly identifies withdrawn records and truncated fields. Does not assess exploitability or install software. One shared-plan call. | Read-only |
Requirements
- • A ToolCargo account with Site Audit activated (free). No OSV account or external API key.
Limitations
- • Known public advisories only. Missing results do not establish safety; version matching and source data can be incomplete or outdated.
- • One package/version and one upstream page per query, at most 20 projected records. nextPageToken skips to the next upstream page, not locally omitted records.
- • Each record: up to 20 aliases/references, 10 severity entries/affected packages/ranges, 30 events per range and 50 explicit versions per affected entry. Details limited to 6,000 characters; truncation identified.
- • No dependency graph scan, installation, exploitability assessment or security verdict. Advisory text and reference URLs are untrusted source data.
Supported clients
“Tested” means we connected that client to this endpoint and ran a tool call ourselves. Recorded client-specific tests currently cover Site Audit. Other connectors use the documented setup until tested in that client.
| Claude Code | API key header | Documented, not yet tested | This endpoint has not yet been tested in this client. See the setup guide. |
| Claude (claude.ai) | OAuth sign-in | Documented, not yet tested | This endpoint has not yet been tested in this client. See the setup guide. |
| Cursor | API key header | Documented, not yet tested | This endpoint has not yet been tested in this client. See the setup guide. |
| VS Code (Copilot agent mode) | API key header | Documented, not yet tested | This endpoint has not yet been tested in this client. See the setup guide. |
| ChatGPT (developer mode) | OAuth sign-in | Documented, not yet tested | This endpoint has not yet been tested in this client. See the setup guide. |
| MCP Inspector | API key header | Documented, not yet tested | This endpoint has not yet been tested in this client. See the setup guide. |
Practical workflows
More in Developer tools
- Hugging Face Hub Research LiveFind models and datasets, then review their public metadata.
- npm Package Intelligence LiveCompare dependencies before adding them to a project.
- PyPI Package Intelligence LiveCompare Python packages before choosing a dependency.
- Rust Crate Research LiveFind Rust crates and inspect releases, features and dependencies.
Pricing
Included with Site Audit. Each successful package query or advisory lookup is one shared-plan call.
Free
$0Try hosted tools with a shared monthly allowance.
50 shared calls/month
Pro
$12/moProposed larger shared allowance; see checkout status on the pricing page.
2,000 shared calls/month
Proposed test price. See the pricing page for checkout status.