Developer · Remote MCP server

Nist Nvd MCP Server

Search and audit NIST NVD CVEs by keyword, severity, CWE, CISA KEV status, and CPE.

What the MCP Registry states

The entry as published to the official MCP Registry (read 2026-10-04), latest version.

Registry name
io.github.cyanheads/nist-nvd-mcp-server
Version
0.3.1
Status
Active
Category
developer
Transport
Streamable HTTP, stdio (local process)
Package
npm
Published
2026-09-20
Updated
2026-09-20
Publisher
cyanheads (GitHub) · 140 servers with pages here
Repository
github.com/cyanheads/nist-nvd-mcp-server
Source
Registry API entry

Remote endpoints

TransportURLHeaders declared
Streamable HTTPhttps://nist-nvd.caseyjhand.com/mcpNone

Packages

RegistryPackageVersionTransportEnvironment variables
npmruntime: bun@cyanheads/nist-nvd-mcp-server0.3.1stdioNVD_API_KEY, NVD_REQUEST_TIMEOUT_MS, MCP_LOG_LEVEL
npmruntime: bun@cyanheads/nist-nvd-mcp-server0.3.1HTTPNVD_API_KEY, NVD_REQUEST_TIMEOUT_MS, MCP_HTTP_HOST, MCP_HTTP_PORT, MCP_HTTP_ENDPOINT_PATH, MCP_AUTH_MODE, MCP_LOG_LEVEL

How to connect Nist Nvd MCP Server

Nist Nvd MCP Server is a remote MCP server: there is nothing to install. Its endpoint is https://nist-nvd.caseyjhand.com/mcp, served over Streamable HTTP. In an assistant that accepts remote MCP servers (often under a setting named connectors, integrations or tools), add a new server and give it this URL; in a client configured by file, add it as a remote (HTTP) server with the same URL.

No headers are declared in the registry entry. If the server needs you to sign in, a client that supports MCP authorization opens the service's own sign-in page when it first connects.

It can also run locally from a Node.js package published to the npm registry: @cyanheads/nist-nvd-mcp-server version 0.3.1. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Node.js; clients usually start it with npx — the usual command is npx -y @cyanheads/nist-nvd-mcp-server@0.3.1; the entry names bun as the runtime. It reads these environment variables: NVD_API_KEY, NVD_REQUEST_TIMEOUT_MS and MCP_LOG_LEVEL; set them in the client's configuration for this server.

It can also run locally from a Node.js package published to the npm registry: @cyanheads/nist-nvd-mcp-server version 0.3.1. The package starts a local server that speaks MCP over Streamable HTTP; the client then connects to it by URL (the entry names bun as the runtime). It reads these environment variables: NVD_API_KEY, NVD_REQUEST_TIMEOUT_MS, MCP_HTTP_HOST, MCP_HTTP_PORT, MCP_HTTP_ENDPOINT_PATH, MCP_AUTH_MODE and MCP_LOG_LEVEL; set them in the client's configuration for this server.

In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):

{
  "mcpServers": {
    "nist-nvd-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@cyanheads/nist-nvd-mcp-server@0.3.1"
      ],
      "env": {
        "NVD_API_KEY": "<value>",
        "NVD_REQUEST_TIMEOUT_MS": "<value>",
        "MCP_LOG_LEVEL": "<value>"
      }
    }
  }
}

Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect

More from cyanheads (GitHub)

ServerRunsEndpoint or package
Mailchimp MCP ServerMailchimp via MCP: draft, test, and send campaigns; manage audiences and subscribers; pull reports.Local · stdio, HTTPnpm: @cyanheads/mailchimp-mcp-server
Medical Codes MCP ServerOffline US medical code lookup and crosswalk — ICD-10-CM/PCS, HCPCS Level II, RxNorm. Keyless.Remote & Local · HTTP, stdiomedical-codes.caseyjhand.com
Met Museum MCP ServerSearch the Met collection, browse by department or update date, fetch full records and CC0 images.Remote & Local · HTTP, stdiomet-museum.caseyjhand.com
Musicbrainz MCP ServerSearch MusicBrainz artists, releases, works, labels; resolve ISRC/ISWC/barcode; fetch cover art.Remote & Local · HTTP, stdiomusicbrainz.caseyjhand.com
National Parks MCP ServerPlan US National Park Service trips — parks, alerts, campgrounds, things to do, events.Remote & Local · HTTP, stdionational-parks.caseyjhand.com
Nhtsa Vehicle Safety MCP ServerDecode VINs, search recalls, complaints, crash ratings, and investigations.Remote & Local · HTTP, stdionhtsa.caseyjhand.com
Noaa Cdo MCP ServerSearch NOAA CDO stations and datasets, fetch historical weather observations.Remote & Local · HTTP, stdionoaa-cdo.caseyjhand.com
Noaa Climate MCP ServerSearch NOAA climate stations and datasets, fetch historical weather observations.Remote & Local · HTTP, stdionoaa-climate.caseyjhand.com
Noaa Marine MCP ServerFind NOAA tide stations and NDBC buoys, fetch tide predictions, currents, and live conditions.Remote & Local · HTTP, stdionoaa-marine.caseyjhand.com
Noaa Spaceweather MCP ServerNOAA SWPC space weather: storm scales, Kp index, aurora forecasts, solar wind, activity, alerts.Remote & Local · HTTP, stdionoaa-spaceweather.caseyjhand.com
Nonprofit Explorer MCP ServerMCP server for nonprofit financials via ProPublica — IRS Form 990 data for 1.8M+ nonprofits.Remote & Local · HTTP, stdiononprofit-explorer.caseyjhand.com
Npi Providers MCP ServerSearch NPPES providers and resolve NUCC specialty codes via MCP over STDIO or Streamable HTTP.Remote & Local · HTTP, stdionpi-providers.caseyjhand.com

More developer servers

All 6,250 →
ServerRunsEndpoint or package
NIRA REPL MCPSecure code execution sandbox for Claude — run Python, JavaScript, and shell commands.Local · stdioPyPI: nira-repl
NiroAI pentester for PRs — finds exploitable bugs and hands your developer agent the fix.Local · stdioMCP Bundle (.mcpb): apxlabs-ai/niro/releases/download/v0.1.61/niro.m
Nis2 Incident Runbook LintReads your incident-response runbook and says which of the three Article 23 clocks it gets wrong.Local · stdionpm: @readystack/nis2-incident-runbook-lint
Nishati MCPMCP server for energy coordination in East Africa (nishati = energy)Local · stdioPyPI: nishati-mcp
nittimProduction-safety audits for AI-generated code, with a fix for every finding.Remote · HTTPnittim.com
Nl Eli MCPMCP server for Dutch consolidated legislation (BWB via KOOP SRU) with verifiable citations.Local · stdioPyPI: nl-eli-mcp
nlqdb — analytical memory for AI agentsAnalytical memory for AI agents: a real Postgres queried in plain English over MCP. One command.Remote · HTTPmcp.nlqdb.com
No CrdDynamic pod spawner & proxy for ephemeral AI agent workspaces on Kubernetes without CRDs.Local · stdionpm: @nogoo9/no-crd