Atlas / MCP servers / cyreslab-ai / ExploitDB

ExploitDBSAFE

mcp/cyreslab-ai/exploitdb

MCP server for Exploit-DB — search public exploits and shellcode by CVE, platform, type, and tags.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
18 18r · 0w · 0d
Transport
stdio
License
MIT
Stars
31
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol server that provides access to ExploitDB functionality, developed by Cyreslab.ai. This server enables AI assistants like Claude to query information about security exploits and vulnerabilities, enhancing cybersecurity research and threat intelligence capabilities.

GitHub Repository: https://github.com/Cyreslab-AI/exploitdb-mcp-server Contact: [email protected]

Features

  • Exploit Search: Search for exploits by keywords, CVE IDs, platforms, and more
  • Exploit Details: Get comprehensive information about specific exploits, including code
  • CVE Lookup: Find all exploits related to specific CVE IDs
  • Recent Exploits: Track newly added exploits
  • Statistics: Get insights into exploit distribution by platform, type, and year
  • Automatic Updates: Keep the database up-to-date with scheduled updates

Installation

Prerequisites

  • Node.js (v16 or higher)
  • npm (v7 or higher)

Installation Steps

  1. Clone the repository:
git clone https://github.com/Cyreslab-AI/exploitdb-mcp-server.git
cd exploitdb-mcp-server
  1. Install dependencies:
npm install
  1. Build the project:
npm run build
  1. Configure the server:
  • Create a .env file in the root directory based on .env.example
  • Adjust settings as needed (data directory, update frequency, etc.)
  1. Initialize the database:
npm run update-db

Note: The initial database update may take several minutes as it processes ~47,000 exploits from the ExploitDB CSV file. The script handles missing or malformed data gracefully by using fallback values for required fields.

  1. Run the server:
node build/index.js

MCP Configuration

To use this server with Claude or other MCP-compatible assistants, add it to y

Read from source at commit d2e2a9e45351OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mcp-exploitdb-server -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-exploitdb-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (18)

18 read · 0 write · 0 destructive.

ToolRiskDescription
batch_get_exploitsreadRetrieve multiple exploits efficiently in one call
compare_exploitsreadCompare multiple exploits side-by-side
export_search_resultsreadExport search results in various formats (JSON, CSV)
find_by_cvereadFind exploits by CVE ID
get_exploitreadGet detailed information about a specific exploit
get_exploit_timelinereadGet chronological timeline of exploits for a CVE or search term
get_platform_statisticsreadGet detailed statistics for a specific platform
get_recent_exploitsreadGet recently added exploits
get_related_exploitsreadFind exploits related to a specific exploit (same platform, similar CVE, etc.)
get_statisticsreadGet statistics about the exploits in the database
get_trending_exploitsreadFind recently added exploits (last 30 days by default)
search_by_authorreadFind all exploits by a specific author
search_by_date_rangereadFind exploits within a specific date range
search_by_platformreadSearch exploits for a specific platform with advanced filters
search_by_tagsreadSearch exploits by ExploitDB
search_by_typereadSearch exploits by type (webapps, remote, local, dos, hardware, shellcode)
search_exploitsreadSearch for exploits in the ExploitDB database
validate_exploit_idreadCheck if an exploit ID exists and is valid
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (3)

LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/server, axios, csv-parser, dotenv, fs-extra, simple-git, sqlite3, sqlite
Why it matters. 13 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
data/exploitdb.sqlite
data/exploitdb.sqlite
Why it matters. 20246528 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
data/files_exploits.csv
data/files_exploits.csv
Why it matters. 10181062 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha d2e2a9e45351full audit observations/trust-audit/mcp-server/cyreslab-ai__exploitdb.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08d2e2a9e45351SAFEB89first audit
06

Questions

What is the ExploitDB MCP server?

MCP server for Exploit-DB — search public exploits and shellcode by CVE, platform, type, and tags.

What tools does ExploitDB expose?

18 in total: 18 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is ExploitDB safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does ExploitDB need?

No credential environment variables were found in its source, so it appears to need none.

How does ExploitDB run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-exploitdb-server at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (d2e2a9e45351), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement