ambolt

All endpoints

Package Vulnerabilities: Known CVEs for npm and PyPI Versions

Check an npm or PyPI package version against a public vulnerability database: advisory ids, aliases (CVE, GHSA), summary, severity label and first fixed version, plus the latest published version. Informational; not a full security audit.

x402: $0.003 per callMCP tool: package_vulnerabilities

Input

ParameterTypeDefaultDescription
ecosystem *string
npm | PyPI
Package ecosystem.
name *stringPackage name, e.g. lodash or requests.
versionstringVersion to check. Default: latest published version.

* required

Source and freshness

Source and licence
OSV.dev (CC BY 4.0 for most data) and the package registry. Not a complete audit: unreported issues are not listed.
Last verified
2026-10-03 (hourly check against the live source)

Use it

HTTP (x402)

curl -i "https://api.ambolt.dev/v1/package-vulnerabilities?ecosystem=npm&name=lodash&version=4.17.20"

Returns 402 Payment Required with the price until an x402 payment is attached; @x402/fetch does this for you. See Get started.

MCP

{ "mcpServers": { "ambolt": { "url": "https://api.ambolt.dev/mcp" } } }
# then call the tool: package_vulnerabilities

Apify

Not published as an Actor yet.

Example response

{
  "ecosystem": "npm",
  "name": "lodash",
  "checkedVersion": "4.17.20",
  "latestVersion": "4.18.1",
  "isLatest": false,
  "deprecated": null,
  "vulnerabilityCount": 5,
  "vulnerabilities": [
    {
      "id": "GHSA-29mw-wpgm-hmr9",
      "aliases": [
        "CVE-2020-28500"
      ],
      "summary": "Regular Expression Denial of Service (ReDoS) in lodash",
      "severity": "MODERATE",
      "firstFixedVersion": "4.17.21",
      "published": "2022-01-06T20:30:46Z",
      "url": "https://osv.dev/vulnerability/GHSA-29mw-wpgm-hmr9"
    },
    {
      "id": "GHSA-35jh-r3h4-6jhm",
      "aliases": [
        "CVE-2021-23337",
        "CVE-2026-4800",
        "GHSA-r5fr-rjxr-66jc"
      ],
      "summary": "Command Injection in lodash",
      "severity": "HIGH",
      "firstFixedVersion": "4.17.21",
      "published": "2021-05-06T16:05:51Z",
      "url": "https://osv.dev/vulnerability/GHSA-35jh-r3h4-6jhm"
    },
    {
      "id": "GHSA-f23m-r3pf-42rh",
      "aliases": [
        "CVE-2025-13465",
        "CVE-2026-2950",
        "GHSA-xxjr-mmjv-4gpg"
      ],
      "summary": "lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`",
      "severity": "MODERATE",
      "firstFixedVersion": "4.18.0",
      "published": "2026-04-01T23:50:27Z",
      "url": "https://osv.dev/vulnerability/GHSA-f23m-r3pf-42rh"
    }
  ],
  "checkedAt": "2026-10-02T21:35:48.558Z",
  "source": "Source: OSV.dev (CC BY 4.0 for most data) and the package registry. Not a complete audit: unreported issues are not listed."
}

Good to know

Guides