# GET /cve: $0.003 per call

Vulnerability lookup for agents: by id (?id=CVE-2021-44228, GHSA-..., PYSEC-..., RUSTSEC-..., GO-...) get the advisory, severity/CVSS, affected packages and fixed versions, exploit probability (EPSS) and whether CISA lists it as exploited in the wild; or by package (?ecosystem=npm&package=lodash[&version=]) list every advisory with the same enrichment.

- **Price:** $0.003 in USDC, the same on Base, Solana, Polygon, Arbitrum. Failed calls are never charged.
- **Free trial:** yes, 20 free calls a day from Claude, Cursor or any MCP client ([set-up](/mcp/setup)).
- **Tier:** live
- **Answers cached for:** 1 hour(s)
- **Data sources:** OSV.dev (free); FIRST EPSS (free); CISA Known Exploited Vulnerabilities (free)
- **Lane:** AI coding agents ([OpenAPI](/openapi/coding.json))
- **Live health:** [status page](/status)

## Free sample

See an answer for the demo input first, free (no payment, 10 a minute): [https://aayatai.com/sample/cve](/sample/cve). It is a stored real answer when we have one, otherwise an example marked `"kind": "illustrative"`.

```bash
curl "https://aayatai.com/sample/cve"
```

## 1. See the price (free)

Call it without paying: you get `402 Payment Required` and a `PAYMENT-REQUIRED` header with the exact price and where to pay.

```bash
curl -i "https://aayatai.com/cve?id=CVE-2021-44228"
```

## 2. Pay and call (TypeScript)

```bash
npm install @x402/fetch @x402/evm viem
```

```ts
import { wrapFetchWithPaymentFromConfig } from "@x402/fetch";
import { ExactEvmScheme } from "@x402/evm";
import { privateKeyToAccount } from "viem/accounts";

// A wallet used only by your agent, holding a little USDC on Base.
const account = privateKeyToAccount(process.env.WALLET_PRIVATE_KEY as `0x${string}`);
const pay = wrapFetchWithPaymentFromConfig(fetch, {
  schemes: [{ network: "eip155:8453", client: new ExactEvmScheme(account) }],
});

const res = await pay("https://aayatai.com/cve?id=CVE-2021-44228");
console.log(await res.json());
```

## 3. Or as an MCP tool

```ts
// MCP server: https://aayatai.com/mcp (Streamable HTTP). With the x402 MCP client (see /start):
const result = await client.callTool("cve", {"id":"CVE-2021-44228"});
```

## Inputs

- `id` (string): Advisory id: CVE-..., GHSA-..., PYSEC-..., RUSTSEC-..., GO-..., MAL-...
- `ecosystem` (string; one of `npm`, `pypi`, `crates`, `go`; default `npm`): Package ecosystem: npm, pypi, crates (Rust) or go (Go modules).
- `package` (string): Or: a package name, to list its advisories.
- `version` (string): With package: only advisories affecting this version.

Bad inputs are rejected with HTTP 400 before any payment is asked for.

## Example answer

```json
{
  "mode": "id",
  "vulnerability": {
    "id": "CVE-2021-44228",
    "aliases": [
      "GHSA-jfh8-c2jp-5v3q"
    ],
    "summary": "Log4Shell: remote code execution in Apache Log4j2",
    "severity": "critical",
    "fixedIn": [
      "2.15.0"
    ],
    "published": "2021-12-10T10:15:09Z",
    "url": "https://osv.dev/vulnerability/CVE-2021-44228",
    "details": "Apache Log4j2 2.0-beta9 through 2.15.0 ... JNDI features ...",
    "cvss": [
      {
        "type": "CVSS_V3",
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      }
    ],
    "modified": "2026-01-01T00:00:00Z",
    "withdrawn": null,
    "affected": [
      {
        "ecosystem": "Maven",
        "package": "org.apache.logging.log4j:log4j-core",
        "fixedIn": [
          "2.15.0"
        ]
      }
    ],
    "references": [
      {
        "type": "ADVISORY",
        "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-44228"
      }
    ],
    "epss": {
      "score": 0.99999,
      "percentile": 1,
      "date": "2026-09-27"
    },
    "knownExploited": {
      "dateAdded": "2021-12-10",
      "dueDate": "2021-12-24",
      "ransomware": true,
      "requiredAction": "Apply updates per vendor instructions."
    },
    "kevChecked": true
  },
  "sources": [
    "OSV.dev",
    "FIRST EPSS",
    "CISA KEV"
  ],
  "checkedAt": "2026-09-28T12:00:00.000Z"
}
```

## Related

- [GET /docs/find](/services/docs-find) ($0.003): Find the AI-ready docs for any library or API: checks the project's docs site (from its npm, PyPI, crates or Go metadata) or any company domain (docs., develope
- [GET /docs/lib](/services/docs-lib) ($0.005): Up-to-date docs for any npm, PyPI, crates or Go library, trimmed for a coding agent's context: finds the project's own llms.txt and docs pages (or the latest re
- [POST /docs/answer](/services/docs-answer) ($0.02): Ask a coding question about any npm, PyPI, crates or Go library and get an answer written only from its current docs (project llms.txt, docs pages or latest REA
- [GET /openapi](/services/openapi) ($0.005): Understand any public API fast: give its OpenAPI/Swagger spec URL, its docs or base URL, or a name from the APIs.guru directory (?api=stripe.com); we find the s
- [GET /library/research](/services/library-research) ($0.10): Premium research report on a library or API for coding agents: reads its current docs for your goal, checks version, safety and repository health, gathers what 
- [GET /package/check](/services/package-check) ($0.005): Should a coding agent install this package?
- [GET /dependency/verdict](/services/dependency-verdict) ($0.03): "Should I use this dependency?" in one call for npm, PyPI, crates or Go: full package safety check (vulnerabilities, malware, typosquats, deprecation, licence, 
- [GET /dependency/report](/services/dependency-report) ($0.08): Premium "should I use this dependency?" report: package safety (vulnerabilities, malware, typosquats, deprecation), GitHub repository health, licence compatibil

New here? [Getting started in 60 seconds](/start). All services: [Aayat AI](/).