Check any MCP server for known CVEs

Paste a server. See the disclosed vulnerabilities in its dependencies in seconds. Free, no login, and we check servers that are new to us live.

In our May 2026 scan of about 14,800 MCP servers, 37% had a known CVE in their dependencies. See the data.

Try one:
How it works: we resolve the server to its repo or package, read its declared dependencies, and check them against the OSV vulnerability database. If it is not in our index yet, we fetch and check it live. Whether a CVE is reachable depends on the installed versions.
We are building a series of free tools for people building with MCP and AI.
Tell us what is hard about building with MCP and AI right now. 3 minutes, no pitch.
Take the survey