ambolt

All guides

Check an npm or PyPI package for known vulnerabilities

Look up advisories for an exact package version and see the first fixed version and the latest release.

Before adding or upgrading a dependency, check the exact version. The endpoint returns known advisories with their ids and aliases (CVE, GHSA), severity labels and the first version that fixes each, plus the latest published version and whether the package is deprecated.

It is a lookup of known issues, not a full security audit. Unreported problems are not listed.

The calls

Each call returns 402 with the price until a payment is attached; an x402 client pays and retries automatically. Calls that fail are not charged. See Get started and the guide for bots and agents for code.

package-vulnerabilities $0.003 per call

Check an npm or PyPI package version against a public vulnerability database: advisory ids, aliases (CVE, GHSA), summary, severity label and first fixed version, plus the latest published version.

curl -i "https://api.ambolt.dev/v1/package-vulnerabilities?ecosystem=npm&name=lodash&version=4.17.20"
Example response
{
  "ecosystem": "npm",
  "name": "lodash",
  "checkedVersion": "4.17.20",
  "latestVersion": "4.18.1",
  "isLatest": false,
  "deprecated": null,
  "vulnerabilityCount": 5,
  "vulnerabilities": [
    {
      "id": "GHSA-29mw-wpgm-hmr9",
      "aliases": [
        "CVE-2020-28500"
      ],
      "summary": "Regular Expression Denial of Service (ReDoS) in lodash",
      "severity": "MODERATE",
      "firstFixedVersion": "4.17.21",
      "published": "2022-01-06T20:30:46Z",
      "url": "https://osv.dev/vulnerability/GHSA-29mw-wpgm-hmr9"
    },
    {
      "id": "GHSA-35jh-r3h4-6jhm",
      "aliases": [
        "CVE-2021-23337",
        "CVE-2026-4800",
        "GHSA-r5fr-rjxr-66jc"
      ],
      "summary": "Command Injection in lodash",
      "severity": "HIGH",
      "firstFixedVersion": "4.17.21",
      "published": "2021-05-06T16:05:51Z",
      "url": "https://osv.dev/vulnerability/GHSA-35jh-r3h4-6jhm"
    },
    {
      "id": "GHSA-f23m-r3pf-42rh",
      "aliases": [
        "CVE-2025-13465",
        "CVE-2026-2950",
        "GHSA-xxjr-mmjv-4gpg"
      ],
      "summary": "lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`",
      "severity": "MODERATE",
      "firstFixedVersion": "4.18.0",
      "published": "2026-04-01T23:50:27Z",
      "url": "https://osv.dev/vulnerability/GHSA-f23m-r3pf-42rh"
    }
  ],
  "checkedAt": "2026-10-02T21:35:48.558Z",
  "source": "Source: OSV.dev (CC BY 4.0 for most data) and the package registry. Not a complete audit: unreported issues are not listed."
}

Questions

Which ecosystems are covered?

npm and PyPI.

Does it scan my whole project?

No. One package version per call.

Use it from an AI agent

Every call is also an MCP tool: add https://api.ambolt.dev/mcp to your agent's server list.