Package Vulnerabilities: Known CVEs for npm and PyPI Versions
Check an npm or PyPI package version against a public vulnerability database: advisory ids, aliases (CVE, GHSA), summary, severity label and first fixed version, plus the latest published version. Informational; not a full security audit.
x402: $0.003 per callMCP tool: package_vulnerabilities
Input
| Parameter | Type | Default | Description |
|---|---|---|---|
ecosystem * | string npm | PyPI | Package ecosystem. | |
name * | string | Package name, e.g. lodash or requests. | |
version | string | Version to check. Default: latest published version. |
* required
Source and freshness
- Source and licence
- OSV.dev (CC BY 4.0 for most data) and the package registry. Not a complete audit: unreported issues are not listed.
- Last verified
- 2026-10-03 (hourly check against the live source)
Use it
HTTP (x402)
curl -i "https://api.ambolt.dev/v1/package-vulnerabilities?ecosystem=npm&name=lodash&version=4.17.20"Returns 402 Payment Required with the price until an x402 payment is attached; @x402/fetch does this for you. See Get started.
MCP
{ "mcpServers": { "ambolt": { "url": "https://api.ambolt.dev/mcp" } } }
# then call the tool: package_vulnerabilities
Apify
Not published as an Actor yet.
Example response
{
"ecosystem": "npm",
"name": "lodash",
"checkedVersion": "4.17.20",
"latestVersion": "4.18.1",
"isLatest": false,
"deprecated": null,
"vulnerabilityCount": 5,
"vulnerabilities": [
{
"id": "GHSA-29mw-wpgm-hmr9",
"aliases": [
"CVE-2020-28500"
],
"summary": "Regular Expression Denial of Service (ReDoS) in lodash",
"severity": "MODERATE",
"firstFixedVersion": "4.17.21",
"published": "2022-01-06T20:30:46Z",
"url": "https://osv.dev/vulnerability/GHSA-29mw-wpgm-hmr9"
},
{
"id": "GHSA-35jh-r3h4-6jhm",
"aliases": [
"CVE-2021-23337",
"CVE-2026-4800",
"GHSA-r5fr-rjxr-66jc"
],
"summary": "Command Injection in lodash",
"severity": "HIGH",
"firstFixedVersion": "4.17.21",
"published": "2021-05-06T16:05:51Z",
"url": "https://osv.dev/vulnerability/GHSA-35jh-r3h4-6jhm"
},
{
"id": "GHSA-f23m-r3pf-42rh",
"aliases": [
"CVE-2025-13465",
"CVE-2026-2950",
"GHSA-xxjr-mmjv-4gpg"
],
"summary": "lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`",
"severity": "MODERATE",
"firstFixedVersion": "4.18.0",
"published": "2026-04-01T23:50:27Z",
"url": "https://osv.dev/vulnerability/GHSA-f23m-r3pf-42rh"
}
],
"checkedAt": "2026-10-02T21:35:48.558Z",
"source": "Source: OSV.dev (CC BY 4.0 for most data) and the package registry. Not a complete audit: unreported issues are not listed."
}
Good to know
- You are charged only when the call succeeds. Invalid input or an unavailable source costs nothing.
- Every response states its source and the time it was fetched.
- Informational only; not financial, legal or tax advice.
- Something wrong or missing? Open an issue on the repository (ambolt-mcp) and a reply follows under the Ambolt name.