81trust / 100

Proxy Cve Lookup

by CVE Vulnerability Lookup in Security & trust

x402 APIPassing, checked 2 h ago

Look up a vulnerability by CVE or GHSA id (NVD: description, CVSS score and vector, CWE, CISA known-exploited flag; OSV: affected packages and fixed versions) or check a package version for known vulnerabilities via OSV.dev (npm, PyPI, Maven, Go, crates.io, RubyGems, NuGet, Packagist, Debian ...). Params: cve_id, or package + ecosystem (+ version, recommended), limit (default 20).

POST https://agentsvc.io/api/v1/proxy/cve-lookup

Last 30 days

All checks passedSome failedAll failedNot checked
Uptime
100%
Response time
30 ms typical, 30 ms slowest 5%
Last check
2 h ago
Next check
any minute now

How to call it

# See the payment challenge (nothing is charged)
curl -i -X POST "https://agentsvc.io/api/v1/proxy/cve-lookup" \
  -H "content-type: application/json" \
  -d '{"cve_id":"CVE-2021-44228"}'
import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { ExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";

const client = new x402Client().register(
  "eip155:8453",
  new ExactEvmScheme(privateKeyToAccount(process.env.AGENT_KEY)),
);
const pay = wrapFetchWithPayment(fetch, client);

// Not sure it's safe to pay? Preflight it first for $0.005:
// GET https://toolvet.app/api/v1/check?url=https%3A%2F%2Fagentsvc.io%2Fapi%2Fv1%2Fproxy%2Fcve-lookup
const res = await pay("https://agentsvc.io/api/v1/proxy/cve-lookup", {
  method: "POST",
  headers: { "content-type": "application/json" },
  body: JSON.stringify({"cve_id":"CVE-2021-44228"}),
});
console.log(await res.json());

Example input

{
  "cve_id": "CVE-2021-44228"
}

Example output

{
  "data": {
    "checked_at": "2026-10-06T14:30:56.665Z",
    "count": 6,
    "query": {
      "ecosystem": "npm",
      "package": "lodash",
      "version": "4.17.15"
    },
    "source": "OSV.dev",
    "vulnerabilities": [
      {
        "affected": [
          {
            "ecosystem": "npm",
            "package": "lodash",
            "ranges": [
              {
                "fixed": "4.17.21",
                "introduced": "4.0.0",
                "last_affected": null
              }
            ]
          },
          {
            "ecosystem": "npm",
            "package": "lodash-es",
            "ranges": [
              {
                "fixed": "4.17.21",
                "introduced": "4.0.0",
                "last_affected": null
              }
            ]
          }
        ],
        "aliases": [
          "CVE-2020-28500"
        ],
        "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
        "cwe": [
          "CWE-1333",
          "CWE-400"
        ],
        "id": "GHSA-29mw-wpgm-hmr9",
        "published": "2022-01-06",
        "references": [
          "https://nvd.nist.gov/vuln/detail/CVE-2020-28500",
          "https://github.com/github/advisory-database/pull/6139"
        ],
        "severity": "MODERATE",
        "summary": "Regular Expression Denial of Service (ReDoS) in lodash",
        "url": "https://osv.dev/vulnerability/GHSA-29mw-wpgm-hmr9"
      }
    ],
    "vulnerable": true
  },
  "success": true
}

Security scan

  • No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.

Recent checks

WhenResultHTTPTimePrice
2 h agoPassed40231 ms$0.009
7 h agoPassed40230 ms$0.009