agentsvc.io

services / cve-lookup

utilityoperational · 1 ms

CVE and Package Vulnerability Lookup

Look up a vulnerability by CVE or GHSA id (NVD: description, CVSS score and vector, CWE, CISA known-exploited flag; OSV: affected packages and fixed versions) or check a package version for known vulnerabilities via OSV.dev (npm, PyPI, Maven, Go, crates.io, RubyGems, NuGet, Packagist, Debian ...). Params: cve_id, or package + ecosystem (+ version, recommended), limit (default 20).

Run free trial ↗3 free calls per day with the example input. Paid: $0.003 USDC, no limit.

Call it

import { wrapFetchWithPayment, x402Client } from "@x402/fetch";
import { registerExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";

const client = new x402Client();
registerExactEvmScheme(client, { signer: privateKeyToAccount(process.env.EVM_PRIVATE_KEY) });
const payFetch = wrapFetchWithPayment(fetch, client);

const res = await payFetch("https://agentsvc.io/api/v1/proxy/cve-lookup", {
  method: "POST",
  headers: { "Content-Type": "application/json" },
  body: JSON.stringify({"cve_id":"CVE-2021-44228"}),
});
const { data, payment } = await res.json();  // payment.transaction = on-chain receipt

Input

FieldTypeDescription
cve_idstringCVE-2021-44228 or GHSA-xxxx-xxxx-xxxx
packagestring
ecosystemstringOSV ecosystem name, case sensitive: npm, PyPI, Maven, Go, crates.io, RubyGems, NuGet, Packagist
versionstring
limitinteger = 20

Output

FieldTypeDescription
queryobject
countinteger
vulnerableboolean
vulnerabilitiesarray
sourcestring
checked_atstring

Example response (data)

{
  "query": {
    "package": "lodash",
    "ecosystem": "npm",
    "version": "4.17.15"
  },
  "count": 6,
  "vulnerable": true,
  "vulnerabilities": [
    {
      "id": "GHSA-29mw-wpgm-hmr9",
      "aliases": [
        "CVE-2020-28500"
      ],
      "summary": "Regular Expression Denial of Service (ReDoS) in lodash",
      "severity": "MODERATE",
      "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "cwe": [
        "CWE-1333",
        "CWE-400"
      ],
      "published": "2022-01-06",
      "affected": [
        {
          "ecosystem": "npm",
          "package": "lodash",
          "ranges": [
            {
              "introduced": "4.0.0",
              "fixed": "4.17.21",
              "last_affected": null
            }
          ]
        },
        {
          "ecosystem": "npm",
          "package": "lodash-es",
          "ranges": [
            {
              "introduced": "4.0.0",
              "fixed": "4.17.21",
              "last_affected": null
            }
          ]
        }
      ],
      "references": [
        "https://nvd.nist.gov/vuln/detail/CVE-2020-28500",
        "https://github.com/github/advisory-database/pull/6139"
      ],
      "url": "https://osv.dev/vulnerability/GHSA-29mw-wpgm-hmr9"
    }
  ],
  "source": "OSV.dev",
  "checked_at": "2026-10-06T14:30:56.665Z"
}