Skip to main content

PostgreSQL CVE & Release Intelligence MCP Server

Project description

pg-cve-mcp — PostgreSQL CVE & Release Intelligence for AI Agents

PyPI version Python versions License

Give your AI assistant direct access to PostgreSQL security intelligence: CVEs, yanked releases, known exploits, and upgrade paths for any version — queried, not browsed.


Why pg-cve-mcp?

Browsing a CVE dashboard is a human habit. Agents need answers, not pages.

pg-cve-mcp turns the curated dataset of the PG_CVE project — the same one powering the PostgreSQL CVE Dashboard — into MCP tools that any AI assistant (opencode, Claude Desktop, etc.) can call directly. What was a static page becomes a first-class, programmatic part of your AI workflow.

Unlike raw NVD feeds, the PG_CVE dataset is manually curated to carry the same judgment a careful DBA would apply:

  • Yanked releases flagged with the real reason (e.g. "Data corruption using CONCURRENTLY")
  • Known exploits confirmed to exist in the wild
  • EOL branches marked, with a synthetic CVE-EOL-WARNING (CVSS 10.0) prepended to unsupported reports
  • Verified CVEs — no false positives from automated scraping

What your agent can now do

Prompt to your agent Tool used Result
"Is PostgreSQL 15.8 safe?" get_cves("15.8") EOL/yanked flags, full CVE list sorted by CVSS
"Compare 16.3 vs 16.4" compare_versions("16.3", "16.4") fixed / new / still-present CVEs
"Should I upgrade from 14.10?" get_upgrade_path("14.10") recommended target + the CVEs it fixes
"Any known exploits right now?" get_exploits() all exploitable CVEs, sorted by CVSS
"What does this database track?" get_summary() stats, EOL and yanked-release overview

Agent-first design

Every tool returns structured JSON, sorted by CVSS (highest first). Tools flag yanked and EOL state explicitly on the version metadata, and get_upgrade_path distinguishes a safe minor upgrade from a forced major one when a branch is at or near end-of-life — so the agent can give advice, not just data.

See real tool outputs in the live demo.


Quick Start

pip install pg-cve-mcp
pg-cve-mcp

Or with npx (no install):

npx -y pg-cve-mcp

MCP Tools

Tool Description
get_cves(version) Complete security report for a version: EOL/yanked status, stats, CVEs sorted by CVSS (a synthetic CVE-EOL-WARNING at 10.0 is prepended for unsupported releases)
compare_versions(v1, v2) Side-by-side CVE comparison (fixed/new/still present) with yanked & EOL flags
get_upgrade_path(from_version) Recommended upgrade (minor by default; major when EOL or next-to-EOL) with fixed CVEs
get_exploits() All CVEs with known public exploits, sorted by CVSS
get_summary() Overview of the tracked CVE database incl. yanked releases

Transports

stdio (default)

Run locally over stdio for opencode, Claude Desktop, and other stdio MCP clients:

pip install -e .
pg-cve-mcp

Streamable HTTP (self-hosted)

For remote or enterprise deployments, serve the same tools over HTTP. Run python run_server.py (or build the Dockerfile); the server listens on $PORT (default 8000) at path /mcp:

python run_server.py
# MCP endpoint: http://127.0.0.1:8000/mcp

Configure any MCP client with the URL, e.g. in opencode.json:

{
  "mcp": {
    "pg-cve-mcp": {
      "type": "remote",
      "url": "http://127.0.0.1:8000/mcp"
    }
  }
}

Configuration

Env Var Default Description
PG_CVE_MCP_TTL 86400 Cache TTL in seconds for CVE data
PG_CVE_MCP_DATA_URL https://meob.github.io/PG_CVE/postgresql_cves.json CVE data source URL
PORT 8000 HTTP port for the Streamable HTTP server (run_server.py)

Development

Run the test suite and linters:

python -m pytest
ruff check src tests
mypy src

Data Source

Data is fetched from the PG_CVE project's GitHub Pages with local caching. Falls back to a bundled copy if the network is unavailable.

Example Prompts

"What CVEs affect PostgreSQL 16.4?"

"Is PostgreSQL 15.8 safe to use?"

"Compare CVEs in 16.3 vs 16.4"

"What's the upgrade path from PostgreSQL 14.10?"

License

Apache 2.0

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

pg_cve_mcp-1.0.2.tar.gz (26.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

pg_cve_mcp-1.0.2-py3-none-any.whl (23.9 kB view details)

Uploaded Python 3

File details

Details for the file pg_cve_mcp-1.0.2.tar.gz.

File metadata

  • Download URL: pg_cve_mcp-1.0.2.tar.gz
  • Upload date:
  • Size: 26.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for pg_cve_mcp-1.0.2.tar.gz
Algorithm Hash digest
SHA256 f0e447c3e0233b6ffa5383e79a0b64f64f137df5705daca29c667caba3536c2a
MD5 908616b56d99be15e35a61b8b8816f77
BLAKE2b-256 e1b021a91c6bd31c711414fc8d7880936f3565ccaf0c300948668828823db5ee

See more details on using hashes here.

File details

Details for the file pg_cve_mcp-1.0.2-py3-none-any.whl.

File metadata

  • Download URL: pg_cve_mcp-1.0.2-py3-none-any.whl
  • Upload date:
  • Size: 23.9 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for pg_cve_mcp-1.0.2-py3-none-any.whl
Algorithm Hash digest
SHA256 d851433df4fa86c6fcf27ca13f4ee902a7db7a060c0337b9533a060917229efb
MD5 522ab584eb41ad0e3b56cc53401d2634
BLAKE2b-256 6751d0954067f9f906ef91715d9e02234fe86296f37b8d349a2862421c8f98d8

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page