<p align="center">
  <a href="README.md">English</a> |
  <a href="README.zh.md">简体中文</a> |
  <a href="README.zh-TW.md">繁體中文</a> |
  <a href="README.ko.md">한국어</a> |
  <a href="README.de.md">Deutsch</a> |
  <a href="README.es.md">Español</a> |
  <a href="README.fr.md">Français</a> |
  <a href="README.it.md">Italiano</a> |
  <a href="README.da.md">Dansk</a> |
  <a href="README.ja.md">日本語</a> |
  <a href="README.pl.md">Polski</a> |
  <a href="README.ru.md">Русский</a> |
  <a href="README.bs.md">Bosanski</a> |
  <a href="README.ar.md">العربية</a> |
  <a href="README.no.md">Norsk</a> |
  <a href="README.pt-BR.md">Português (Brasil)</a> |
  <a href="README.th.md">ไทย</a> |
  <a href="README.tr.md">Türkçe</a> |
  <a href="README.uk.md">Українська</a> |
  <a href="README.bn.md">বাংলা</a> |
  <a href="README.el.md">Ελληνικά</a> |
  <strong>Tiếng Việt</strong> |
  <a href="README.hi.md">हिन्दी</a>
</p>

<p align="center">
  <br>
  <picture>
    <source media="(prefers-color-scheme: dark)" srcset="https://raw.githubusercontent.com/badchars/cve-mcp/main/.github/banner-dark.svg">
    <source media="(prefers-color-scheme: light)" srcset="https://raw.githubusercontent.com/badchars/cve-mcp/main/.github/banner-light.svg">
    <img alt="cve-mcp" src="https://raw.githubusercontent.com/badchars/cve-mcp/main/.github/banner-dark.svg" width="700">
  </picture>
</p>

<h3 align="center">Thong tin tinh bao CVE & lo hong cho AI agent.</h3>

<p align="center">
  NVD, EPSS, CISA KEV, GitHub Advisory, OSV, Shodan, VulnCheck, Vulners, Nuclei, Metasploit, CIRCL, AttackerKB va MITRE ATT&amp;CK &mdash; hop nhat trong mot MCP server duy nhat.<br>
  AI agent cua ban nhan duoc <b>thong tin tinh bao lo hong theo yeu cau</b>, khong phai bao cao 200 trang.
</p>

<br>

<p align="center">
  <a href="#van-de">Van De</a> &bull;
  <a href="#khac-biet-nhu-the-nao">Khac Biet Nhu The Nao</a> &bull;
  <a href="#bat-dau-nhanh">Bat Dau Nhanh</a> &bull;
  <a href="#ai-co-the-lam-gi">AI Co The Lam Gi</a> &bull;
  <a href="#tham-chieu-cong-cu-41-cong-cu">Cong Cu</a> &bull;
  <a href="#nguon-du-lieu">Nguon Du Lieu</a> &bull;
  <a href="#kien-truc">Kien Truc</a>
</p>

<p align="center">
  <a href="https://www.npmjs.com/package/cve-mcp"><img src="https://img.shields.io/npm/v/cve-mcp.svg" alt="npm"></a>
  <a href="LICENSE"><img src="https://img.shields.io/badge/license-MIT-blue.svg" alt="License"></a>
  <img src="https://img.shields.io/badge/runtime-Bun-f472b6" alt="Bun">
  <img src="https://img.shields.io/badge/protocol-MCP-8b5cf6" alt="MCP">
  <img src="https://img.shields.io/badge/tools-41-f97316" alt="41 Tools">
  <img src="https://img.shields.io/badge/sources-11-ef4444" alt="11 Sources">
</p>

---

## Van De

Thong tin tinh bao lo hong bi phan tan tren nhieu co so du lieu. NVD co chi tiet CVE. EPSS cho ban biet xac suat khai thac. CISA KEV theo doi cac lo hong dang bi khai thac. GitHub Advisory bao phu cac goi ma nguon mo. OSV anh xa lo hong den cac phien ban goi cu the. Shodan theo doi su pho bien tren internet. Nuclei va Metasploit cho ban biet co exploit hoat dong hay khong. Khong co cong cu nao tong hop tat ca, va khong co cong cu nao hoat dong voi AI agent.

```
Quy trinh truyen thong:
  tim kiem NVD de lay chi tiet CVE           →  dieu huong giao dien Web UI phuc tap
  kiem tra EPSS de danh gia rui ro khai thac  →  API rieng, dinh dang rieng
  tra cuu trang thai CISA KEV                 →  tai xuong JSON feed thu cong
  tim kiem GitHub advisories                  →  lai them mot giao dien nua
  truy van OSV de biet anh huong goi          →  API khac, schema khac
  kiem tra Shodan de biet su pho bien          →  dang ky rieng
  tim Nuclei/MSF exploits                     →  tim kiem GitHub thu cong
  anh xa den ATT&CK techniques                →  tra cuu MITRE rieng
  tuong quan moi thu                          →  sao chep-dan vao bang tinh
  ──────────────────────────────────
  Tong cong: 30+ phut cho moi CVE, lau hon cho phan loai hang loat
```

**cve-mcp** cung cap cho AI agent cua ban 41 cong cu qua [Model Context Protocol](https://modelcontextprotocol.io). Agent truy van 11 nguon song song, tuong quan du lieu, phat hien tin hieu vu khi hoa, tinh diem rui ro va cho ban biet chinh xac dieu gi quan trong.

```
Voi cve-mcp:
  Ban: "Uu tien 10 CVE nay theo rui ro khai thac thuc te"

  Agent: → lay diem CVSS tu NVD
         → lay xac suat khai thac EPSS cho tung CVE
         → kiem tra CISA KEV cho cac lo hong dang bi khai thac
         → doi chieu cheo GitHub advisories cho ban va
         → "3 lo hong nghiem trong: CVE-2024-3400 (EPSS 97%, trong KEV),
            CVE-2023-44487 (HTTP/2 rapid reset, EPSS 96%),
            CVE-2021-44228 (Log4Shell, EPSS 97%, trong KEV).
            Day la ban va va cac phien ban bi anh huong..."
```

---

## Khac Biet Nhu The Nao

Cac cong cu hien co cho ban du lieu tho. cve-mcp cho AI agent cua ban kha nang phan tich lo hong.

<table>
<thead>
<tr>
<th></th>
<th>Cong Cu Truyen Thong</th>
<th>cve-mcp</th>
</tr>
</thead>
<tbody>
<tr>
<td><b>Giao dien</b></td>
<td>Web UI / CLI / goi API truc tiep</td>
<td>MCP &mdash; AI agent goi cong cu qua hoi thoai</td>
</tr>
<tr>
<td><b>Nguon du lieu</b></td>
<td>Moi lan mot co so du lieu</td>
<td>11 nguon song song: NVD, EPSS, KEV, GHSA, OSV, Shodan, VulnCheck, Vulners, Nuclei, Metasploit, CIRCL</td>
</tr>
<tr>
<td><b>Cham diem rui ro</b></td>
<td>Chi CVSS (muc do nghiem trong, khong phai kha nang khai thac)</td>
<td>CVSS &times; EPSS &times; KEV &times; He so nhan Exploit (Nuclei/MSF) = rui ro thuc te</td>
</tr>
<tr>
<td><b>Tuong quan</b></td>
<td>Sao chep-dan thu cong</td>
<td>Agent lam giau: "CVSS 9.8, EPSS 97%, trong KEV, co Nuclei template, co MSF module, anh xa den T1190"</td>
</tr>
<tr>
<td><b>Phan loai hang loat</b></td>
<td>Moi lan mot CVE</td>
<td>Agent uu tien 50 CVE trong mot cuoc hoi thoai</td>
</tr>
<tr>
<td><b>Anh huong goi</b></td>
<td>Tra cuu OSV/GHSA rieng</td>
<td>Agent tu dong tim cac goi va phien ban bi anh huong</td>
</tr>
<tr>
<td><b>Phu thuoc</b></td>
<td>Cong cu CLI nang, moi truong Python</td>
<td>2 runtime dependencies, chay voi npx</td>
</tr>
</tbody>
</table>

---

## Bat Dau Nhanh

### Tuy chon 1: npx (khong can cai dat)

```bash
npx cve-mcp
```

### Tuy chon 2: Clone

```bash
git clone https://github.com/badchars/cve-mcp.git
cd cve-mcp
bun install
```

### Bien moi truong (tuy chon)

```bash
# Tang rate limit NVD tu 5 len 50 yeu cau moi 30 giay
export NVD_API_KEY=your-nvd-api-key

# Kich hoat tim kiem GitHub Advisory (60 → 5000 yeu cau/gio)
export GITHUB_TOKEN=ghp_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

# VulnCheck extended KEV, CPE, PURL search
export VULNCHECK_API_KEY=your-vulncheck-key

# Vulners vulnerability search tren 200+ nguon
export VULNERS_API_KEY=your-vulners-key

# AttackerKB community assessments
export ATTACKERKB_API_KEY=your-attackerkb-key
```

Tat ca deu tuy chon. Server hoat dong ma khong can chung — chi voi rate limit thap hon hoac it du lieu hon.

### Ket noi voi AI agent cua ban

<details open>
<summary><b>Claude Code</b></summary>

```bash
# Voi npx
claude mcp add cve-mcp -- npx cve-mcp

# Voi ban clone cuc bo
claude mcp add cve-mcp -- bun run /path/to/cve-mcp/src/index.ts
```

</details>

<details>
<summary><b>Claude Desktop</b></summary>

Them vao `~/Library/Application Support/Claude/claude_desktop_config.json`:

```json
{
  "mcpServers": {
    "cve-mcp": {
      "command": "npx",
      "args": ["cve-mcp"],
      "env": {
        "NVD_API_KEY": "optional-key",
        "GITHUB_TOKEN": "optional-token",
        "VULNCHECK_API_KEY": "optional-key",
        "VULNERS_API_KEY": "optional-key",
        "ATTACKERKB_API_KEY": "optional-key"
      }
    }
  }
}
```

</details>

<details>
<summary><b>Cursor / Windsurf / cac MCP client khac</b></summary>

Cung dinh dang JSON config. Tro lenh den `npx cve-mcp` hoac duong dan cai dat cua ban.

</details>

### Bat dau truy van

```
Ban: "Ban biet gi ve CVE-2024-3400?"
```

Vay thoi. Agent se xu ly phan con lai.

---

## AI Co The Lam Gi

### Ung Pho Su Co

```
Ban: "Chung toi bi tan cong boi CVE-2024-3400. Cho toi moi thu."

Agent: → cve_enrich {cveId: "CVE-2024-3400"}
       → NVD: PAN-OS command injection, CVSS 10.0
       → EPSS: 97.2% xac suat khai thac
       → KEV: Them vao 2024-04-12, han chot 2024-05-01
       → Shodan: 4 CPEs, pho bien tren internet
       → Nuclei: Co detection template (nghiem trong)
       → Metasploit: Co exploit module (excellent rank)
       → "Nghiem trong. Da vu khi hoa — ca Nuclei va MSF modules deu co.
          PAN-OS GlobalProtect, phien ban < 10.2.9-h1.
          Va ngay lap tuc. Han chot CISA: 1 thang 5."
```

### Uu Tien Lo Hong

```
Ban: "Uu tien cac CVE tu ban quet: CVE-2021-44228, CVE-2024-3400,
      CVE-2023-44487, CVE-2024-21762, CVE-2023-4966"

Agent: → cve_prioritize {cves: [...]}
       → Xep hang theo CVSS × EPSS × he so nhan KEV
       → "#1: CVE-2024-3400 (rui ro: 19.44, CVSS 10.0, EPSS 97%, KEV)
          #2: CVE-2021-44228 (rui ro: 19.40, CVSS 10.0, EPSS 97%, KEV)
          #3: CVE-2023-4966 (rui ro: 19.10, CVSS 9.4, EPSS 97%, KEV)
          Ca 5 deu trong CISA KEV — va tat ca ngay lap tuc."
```

### Kiem Tra Phu Thuoc

```
Ban: "Kiem tra xem lodash 4.17.20 va django 3.2.0 co lo hong da biet khong"

Agent: → osv_batch {queries: [
          {package: "lodash", version: "4.17.20", ecosystem: "npm"},
          {package: "django", version: "3.2.0", ecosystem: "PyPI"}
       ]}
       → "lodash 4.17.20: 3 lo hong (prototype pollution)
          django 3.2.0: 12 lo hong (SQL injection, XSS)
          Nang cap lodash len 4.17.21+, django len 4.2+"
```

### Giam Sat Moi De Doa

```
Ban: "CVE nao co kha nang bi khai thac cao nhat hien tai?"

Agent: → cve_trending {limit: 10, minEpss: 0.9}
       → "Top 10 theo xac suat khai thac:
          1. CVE-2024-3400 — PAN-OS (EPSS 97.2%, CVSS 10.0, KEV)
          2. CVE-2023-44487 — HTTP/2 Rapid Reset (EPSS 96.5%, CVSS 7.5, KEV)
          ..."
```

### Phan Tich Sau CVSS (v3.1 & v4.0)

```
Ban: "Phan tich CVSS v4.0 vector nay: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"

Agent: → cvss_parse {vector: "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}
       → "CVSS v4.0 — Diem: 9.3 (NGHIEM TRONG)
          Tan cong qua mang, do phuc tap thap, khong co yeu cau tan cong.
          Khong can dac quyen, khong can tuong tac nguoi dung.
          He thong de bi tan cong: anh huong day du C/I/A.
          He thong tiep theo: khong anh huong."
```

### ATT&CK Mapping

```
Ban: "Anh xa CVE-2024-3400 den MITRE ATT&CK techniques"

Agent: → cve_to_attack {cweIds: ["CWE-77"]}
       → "CWE-77 (Command Injection) anh xa den:
          T1059 — Command and Scripting Interpreter (Execution)
          T1190 — Exploit Public-Facing Application (Initial Access)"
```

---

## Tham Chieu Cong Cu (41 cong cu)

<details>
<summary><b>NVD (4)</b></summary>

| Cong cu | Mo ta |
|------|-------------|
| `nvd_search` | Tim kiem CVE theo tu khoa, muc do nghiem trong, CWE, khoang thoi gian |
| `nvd_get` | Lay chi tiet CVE day du (CVSS, CWE, CPE, tham chieu) |
| `nvd_recent` | CVE duoc cong bo/sua doi gan day |
| `cve_by_product` | Tim CVE theo ten san pham (khop tu khoa CPE) |

</details>

<details>
<summary><b>EPSS (2)</b></summary>

| Cong cu | Mo ta |
|------|-------------|
| `epss_score` | Xac suat khai thac EPSS cho mot hoac nhieu CVE |
| `epss_top` | CVE hang dau theo xac suat khai thac |

</details>

<details>
<summary><b>KEV (3)</b></summary>

| Cong cu | Mo ta |
|------|-------------|
| `kev_check` | Kiem tra xem CVE co trong danh muc CISA Known Exploited Vulnerabilities khong |
| `kev_search` | Tim KEV theo nha cung cap, san pham hoac tu khoa |
| `kev_recent` | Muc KEV duoc them gan day |

</details>

<details>
<summary><b>GHSA (2)</b></summary>

| Cong cu | Mo ta |
|------|-------------|
| `ghsa_search` | Tim GitHub security advisories theo tu khoa, he sinh thai, muc do nghiem trong |
| `ghsa_get` | Lay chi tiet advisory theo GHSA ID hoac CVE ID |

</details>

<details>
<summary><b>OSV (3)</b></summary>

| Cong cu | Mo ta |
|------|-------------|
| `osv_query` | Truy van lo hong cho phien ban goi cu the |
| `osv_get` | Lay chi tiet lo hong theo OSV/GHSA/CVE ID |
| `osv_batch` | Truy van hang loat nhieu goi cung luc |

</details>

<details>
<summary><b>Exploit (1)</b></summary>

| Cong cu | Mo ta |
|------|-------------|
| `exploit_search` | Tim PoC exploit cong khai (GitHub repositories) |

</details>

<details>
<summary><b>Shodan (3)</b></summary>

| Cong cu | Mo ta |
|------|-------------|
| `shodan_cve` | Tra cuu CVE qua Shodan CVEDB (EPSS, KEV, CPE tich hop, khong can xac thuc) |
| `shodan_product` | Tim CVE theo ten san pham/nha cung cap qua Shodan |
| `shodan_ip_vulns` | Lay lo hong da biet cho mot IP address (InternetDB) |

</details>

<details>
<summary><b>VulnCheck (3)</b></summary>

| Cong cu | Mo ta |
|------|-------------|
| `vulncheck_kev` | Danh muc KEV mo rong (~80% nhieu muc hon CISA) |
| `vulncheck_cpe` | Tim CVE theo CPE string |
| `vulncheck_purl` | Tim CVE theo Package URL (purl) |

</details>

<details>
<summary><b>Vulners (2)</b></summary>

| Cong cu | Mo ta |
|------|-------------|
| `vulners_lookup` | Chi tiet CVE tu Vulners (200+ nguon, exploit refs) |
| `vulners_search` | Tim kiem lo hong full-text tren co so du lieu Vulners |

</details>

<details>
<summary><b>Nuclei & Metasploit (2)</b></summary>

| Cong cu | Mo ta |
|------|-------------|
| `nuclei_check` | Kiem tra xem co Nuclei detection template cho CVE khong |
| `msf_check` | Kiem tra xem co Metasploit exploit module cho CVE khong |

</details>

<details>
<summary><b>CPE (2)</b></summary>

| Cong cu | Mo ta |
|------|-------------|
| `cpe_search` | Tim tu dien NVD CPE theo tu khoa |
| `cpe_match` | Lay CPE matches cho mot CVE cu the |

</details>

<details>
<summary><b>CIRCL (1)</b></summary>

| Cong cu | Mo ta |
|------|-------------|
| `circl_cve` | CIRCL CVE enrichment (CAPEC, tham chieu thay the, impact vectors) |

</details>

<details>
<summary><b>AttackerKB (1)</b></summary>

| Cong cu | Mo ta |
|------|-------------|
| `attackerkb_assess` | Danh gia cong dong tu AttackerKB (attacker value, exploitability) |

</details>

<details>
<summary><b>ATT&CK (1)</b></summary>

| Cong cu | Mo ta |
|------|-------------|
| `cve_to_attack` | Anh xa CVE CWE IDs den MITRE ATT&CK techniques va tactics |

</details>

<details>
<summary><b>CWE (4)</b></summary>

| Cong cu | Mo ta |
|------|-------------|
| `cwe_lookup` | Tra cuu diem yeu CWE theo ID hoac tim theo tu khoa (DB tinh) |
| `cwe_get` | Chi tiet CWE day du tu MITRE API (1000+ CWEs, giam thieu, vi du) |
| `cwe_hierarchy` | Phan cap CWE parent/child tu MITRE API |
| `cwe_top25` | MITRE CWE Top 25 Most Dangerous Software Weaknesses |

</details>

<details>
<summary><b>CVSS (1)</b></summary>

| Cong cu | Mo ta |
|------|-------------|
| `cvss_parse` | Phan tich va giai thich chuoi vector CVSS v3.1 hoac v4.0 voi tinh diem |

</details>

<details>
<summary><b>Meta (6)</b></summary>

| Cong cu | Mo ta |
|------|-------------|
| `cve_enrich` | Lam giau day du: NVD + EPSS + KEV + GHSA + OSV + Shodan + Nuclei + MSF song song |
| `cve_prioritize` | Xep hang CVE theo rui ro (CVSS &times; EPSS &times; KEV &times; He so nhan Exploit) |
| `cve_trending` | CVE dang trending theo xac suat khai thac |
| `cve_compare` | So sanh hai CVE canh nhau |
| `cve_list_sources` | Liet ke tat ca 11 nguon du lieu va tinh trang kha dung |
| `cve_report` | Tao bao cao lo hong dang markdown |

</details>

---

## Nguon Du Lieu

| Nguon | Xac thuc | Cung cap gi |
|--------|------|-----------------|
| [NVD](https://nvd.nist.gov/) | `NVD_API_KEY` tuy chon | Chi tiet CVE, diem CVSS, anh xa CWE, san pham bi anh huong CPE, tham chieu |
| [EPSS](https://www.first.org/epss/) | Khong | Diem xac suat khai thac (0-1) va xep hang phan vi |
| [CISA KEV](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) | Khong | Lo hong da biet dang bi khai thac voi han chot khac phuc |
| [GitHub Advisory](https://github.com/advisories) | `GITHUB_TOKEN` tuy chon | Advisory bao mat ma nguon mo, goi bi anh huong, muc do nghiem trong |
| [OSV](https://osv.dev/) | Khong | Du lieu lo hong cap goi tren 16+ he sinh thai |
| [Shodan CVEDB](https://cvedb.shodan.io/) | Khong | Tra cuu CVE voi EPSS/KEV/CPE tich hop, quet lo hong IP |
| [VulnCheck](https://vulncheck.com/) | `VULNCHECK_API_KEY` tuy chon | KEV mo rong (~80% nhieu hon CISA), tim kiem lo hong CPE/PURL |
| [Vulners](https://vulners.com/) | `VULNERS_API_KEY` tuy chon | Tim kiem lo hong tren 200+ nguon, tham chieu exploit |
| [Nuclei Templates](https://github.com/projectdiscovery/nuclei-templates) | Khong | Kiem tra su ton tai cua CVE detection template (muc do nghiem trong, tags) |
| [Metasploit](https://github.com/rapid7/metasploit-framework) | Khong | Kiem tra su ton tai cua exploit module (loai, rank, path) |
| [CIRCL](https://cve.circl.lu/) | Khong | CVE enrichment voi CAPEC mapping, tham chieu thay the, impact vectors |
| [AttackerKB](https://attackerkb.com/) | `ATTACKERKB_API_KEY` tuy chon | Danh gia cong dong (attacker value, exploitability ratings) |
| [MITRE ATT&CK](https://attack.mitre.org/) | Khong | Anh xa CWE-to-ATT&CK technique (tactics, techniques) |
| [MITRE CWE](https://cwe-api.mitre.org/) | Khong | Co so du lieu CWE day du (1000+ diem yeu, phan cap, giam thieu) |

### Cong Thuc Diem Rui Ro

```
Diem Rui Ro = Diem Co So CVSS × Diem EPSS × He So Nhan KEV × He So Nhan Exploit

Trong do:
  Diem Co So CVSS  = 0-10 (muc do nghiem trong tu NVD)
  Diem EPSS         = 0-1 (xac suat khai thac tu FIRST)
  He So Nhan KEV    = 2 neu trong CISA KEV, 1 neu khong
  He So Nhan Exploit = 1.5 neu co Nuclei template HOAC Metasploit module, 1 neu khong
```

Cong thuc nay cho diem rui ro thuc te can bang giua muc do nghiem trong (CVSS) voi kha nang khai thac thuc te (EPSS), khai thac dang hoat dong da biet (KEV) va tin hieu vu khi hoa (cong cu exploit cong khai).

---

## Kien Truc

```
src/
├── index.ts                    Diem vao + MCP stdio
├── types/
│   └── index.ts                ToolDef, ToolContext, ToolResult, kieu API
├── protocol/
│   ├── tools.ts                41 dinh nghia cong cu (Zod schemas)
│   └── mcp-server.ts           MCP server + stdio transport
├── nvd/
│   ├── index.ts                NVD API v2 — search, get, recent
│   └── cpe.ts                  Tim kiem san pham/CPE
├── epss/
│   └── index.ts                EPSS — score, top
├── kev/
│   └── index.ts                KEV — check, search, recent (cached)
├── ghsa/
│   └── index.ts                GitHub Advisory — search, get
├── osv/
│   └── index.ts                OSV — query, get, batch
├── exploit/
│   └── index.ts                Tim PoC qua GitHub repos
├── shodan/
│   └── index.ts                Shodan CVEDB + InternetDB (khong can xac thuc)
├── vulncheck/
│   └── index.ts                VulnCheck KEV, CPE, PURL
├── vulners/
│   └── index.ts                Vulners search + lookup
├── nuclei/
│   └── index.ts                Kiem tra su ton tai Nuclei template
├── metasploit/
│   └── index.ts                Kiem tra MSF module (cached metadata)
├── cpe/
│   └── index.ts                NVD CPE dictionary API
├── circl/
│   └── index.ts                CIRCL CVE enrichment
├── attackerkb/
│   └── index.ts                AttackerKB assessments
├── attack/
│   └── index.ts                CWE → MITRE ATT&CK mapping
├── cwe/
│   └── index.ts                CWE API (MITRE) + static fallback
├── cvss/
│   └── index.ts                CVSS v3.1 + v4.0 parser + calculator
├── meta/
│   ├── enrich.ts               Lam giau CVE day du (8 nguon song song)
│   ├── prioritize.ts           Xep hang CVE dua tren rui ro
│   ├── trending.ts             CVE trending theo EPSS
│   ├── compare.ts              So sanh CVE canh nhau
│   └── sources.ts              Kiem tra tinh trang 11 nguon
└── utils/
    ├── rate-limiter.ts          Bo gioi han toc do dua tren hang doi
    └── cache.ts                 TTL cache
```

**Quyet dinh thiet ke:**

- **Tinh bao, khong phai kiem toan** &mdash; Khac voi [cloud-audit-mcp](https://github.com/badchars/cloud-audit-mcp) va [github-security-mcp](https://github.com/badchars/github-security-mcp), day la cong cu du lieu. Khong co CheckResult, khong co tich luy phat hien. Moi truy van doc lap va khong trang thai.
- **Lam giau song song** &mdash; `cve_enrich` goi 8 nguon qua `Promise.allSettled`. Neu mot nguon bi loi, cac nguon con lai van tra ve du lieu.
- **Phat hien vu khi hoa** &mdash; Kiem tra su ton tai cua Nuclei template va Metasploit module de danh dau CVE co cong cu exploit cong khai.
- **Bo gioi han toc do dung chung** &mdash; Tat ca module NVD dung chung mot instance `RateLimiter` (6 giay giua cac yeu cau) de tranh loi 429.
- **Cache KEV + MSF** &mdash; Danh muc KEV (~1200 muc) va MSF module metadata (~15MB) duoc tai mot lan, cache voi TTL 1 gio.
- **CWE dual-mode** &mdash; MITRE CWE REST API cho chi tiet day du (1000+ CWEs), voi static fallback 40+ muc khi API khong kha dung.
- **CVSS v3.1 + v4.0** &mdash; Tu dong phat hien phien ban tu vector prefix. V4.0 su dung phuong phap MacroVector scoring.
- **ATT&CK mapping** &mdash; Bang CWE-to-technique tinh (33 muc CWE → ATT&CK techniques). Khong can goi API.
- **2 dependencies** &mdash; `@modelcontextprotocol/sdk` va `zod`. Khong co gi khac.

---

## Han Che

- NVD API khong co `NVD_API_KEY` bi gioi han 5 yeu cau moi 30 giay. Dat key cho su dung production
- Tim kiem GitHub Advisory khong co `GITHUB_TOKEN` bi gioi han 60 yeu cau moi gio
- VulnCheck, Vulners va AttackerKB yeu cau API keys cho chuc nang day du
- Tim kiem exploit su dung tim kiem GitHub repository co rate limit rieng
- MSF module metadata (~15MB) duoc tai khi su dung lan dau — cuoc goi `msf_check` dau tien se cham hon
- Cham diem CVSS v4.0 su dung MacroVector approximation (dac ta chinh xac rat phuc tap)
- ATT&CK mapping bao phu 33 muc CWE — CWE khong pho bien co the khong anh xa duoc
- macOS / Linux (Windows chua duoc kiem thu)

---

## Mot Phan cua MCP Security Suite

| Du an | Linh vuc | Cong cu |
|---|---|---|
| [hackbrowser-mcp](https://github.com/badchars/hackbrowser-mcp) | Kiem thu bao mat qua trinh duyet | 39 cong cu, Firefox, kiem thu injection |
| [cloud-audit-mcp](https://github.com/badchars/cloud-audit-mcp) | Bao mat dam may (AWS/Azure/GCP) | 38 cong cu, 60+ kiem tra |
| [github-security-mcp](https://github.com/badchars/github-security-mcp) | Tinh trang bao mat GitHub | 39 cong cu, 45 kiem tra |
| **cve-mcp** | Tinh bao lo hong | 41 cong cu, 11 nguon |

---

<p align="center">
<b>Chi danh cho kiem thu va danh gia bao mat duoc uy quyen.</b><br>
Luon dam bao ban co su uy quyen phu hop truoc khi kiem thu he thong.
</p>

<p align="center">
  <a href="LICENSE">MIT License</a> &bull; Xay dung voi Bun + TypeScript
</p>
