Resolve any CVE identifier into a full attack-surface / exploitability / remediation report, backed by NVD + Exploit-DB and written by Claude.
Every intern/junior security engineer spends the first hour of any CVE ticket doing the same thing: pull the NVD entry, hunt for a PoC on Exploit-DB, cross-reference the CVSS vector, then write the same three paragraphs about attack surface and remediation. CVE Advisor collapses that hour into a single API call — you pass a CVE ID, it returns the structured NVD data, the PoC links, and a Claude-written Markdown report you can paste straight into a ticket. Optionally spins a Docker lab container so you can reproduce the bug.
git clone https://github.com/Danush-Aries/cve-advisor.git
cd cve-advisor
python -m venv .venv && source .venv/bin/activate
pip install -r requirements.txt
cp .env.example backend/.env # add ANTHROPIC_API_KEY
uvicorn backend.main:app --reload --port 8000
curl http://localhost:8000/api/cve/CVE-2021-44228 | jq .Interactive docs: http://localhost:8000/docs.
- NVD 2.0 client (
backend/services/nvd_client.py) — async httpx, extracts CVSS v3.1 / v3.0 / v2 metrics in that order of preference. Handles missing metric keys instead of KeyError-ing. - Exploit-DB fan-out — hits the AJAX JSON endpoint (
www.exploit-db.com/search), falls back to the search HTML if the JSON API is rate-limited. - AsyncAnthropic analyser —
claude-opus-4-5gets the NVD summary + PoC links + CVSS vector, returns a 3-section Markdown report (Attack Surface / Exploitability / Remediation). - File-based cache (7-day TTL) sits in front of both NVD and Exploit-DB — repeat lookups are free and don't burn NVD's 5 req / 30 sec limit.
- Docker lab endpoint (
POST /api/lab/build) usesdocker-pyto boot a sandboxed reproduction container (e.g.vulhub/log4j:2.14.1) so you can actually pop the bug you just read about.
curl http://localhost:8000/api/cve/CVE-2021-44228Returns structured NVD data + PoC links + a Claude-written Markdown report with Attack Surface / Exploitability / Remediation sections.
import httpx
async def analyse(cve_id: str):
async with httpx.AsyncClient() as client:
response = await client.get(f"http://localhost:8000/api/cve/{cve_id}")
response.raise_for_status()
return response.json()curl -X POST http://localhost:8000/api/lab/build \
-H "Content-Type: application/json" \
-d '{"image_name": "vulhub/log4j:2.14.1", "cve_id": "CVE-2021-44228"}'Requires Docker daemon and the docker Python package.
docker build -t cve-advisor .
docker run -p 8000:8000 \
-e ANTHROPIC_API_KEY=your_key \
-e NVD_API_KEY=your_nvd_key \
cve-advisor| Variable | Required | Description |
|---|---|---|
ANTHROPIC_API_KEY |
Yes | Anthropic API key for Claude analysis |
NVD_API_KEY |
No | NVD API key (higher rate limits; free to register) |
CORS_ORIGINS |
No | Comma-separated allowed origins (default: *) |
DOCKER_HOST |
No | Docker daemon socket (default: system default) |
FastAPI + Uvicorn · httpx (async) · Anthropic Python SDK (AsyncAnthropic) · claude-opus-4-5 · Docker SDK for Python · Pydantic v2 · pytest + pytest-asyncio.
cve-advisor/
├── backend/
│ ├── main.py # FastAPI app, routes
│ ├── models/cve.py # Pydantic response model
│ └── services/
│ ├── nvd_client.py # NVD + Exploit-DB clients
│ ├── ai_analyzer.py # AsyncAnthropic Claude integration
│ └── lab_manager.py # Docker lab container router
├── tests/
├── .env.example
├── Dockerfile
└── requirements.txt
PRs welcome. New source clients (Vulners, GitHub Security Advisories, CISA KEV) go in backend/services/ and only need to return a normalised dict — the analyser prompt already handles source-agnostic evidence.
MIT — see LICENSE.
- ponytail-for-python — code intelligence for Python codebases
- Agentic_Systems — reference implementations of agent patterns
- autonomous-coding-agent — full-auto engineering agent
- computer-use-agent — Claude drives your desktop via VNC
- browser-automation-agent — Claude drives Playwright
- blinkchat — realtime chat with vibes
⭐ If this project helps you, star it — stars are how open-source tools get found, and every one directly supports more development.
· Found a bug? Open an issue · Want to chat? Discussions · Contribute? See CONTRIBUTING.md ·