Skip to content

Repository files navigation

CVE Advisor — Any CVE → Claude-written triage in seconds

Resolve any CVE identifier into a full attack-surface / exploitability / remediation report, backed by NVD + Exploit-DB and written by Claude.

build license python fastapi claude

Why this exists

Every intern/junior security engineer spends the first hour of any CVE ticket doing the same thing: pull the NVD entry, hunt for a PoC on Exploit-DB, cross-reference the CVSS vector, then write the same three paragraphs about attack surface and remediation. CVE Advisor collapses that hour into a single API call — you pass a CVE ID, it returns the structured NVD data, the PoC links, and a Claude-written Markdown report you can paste straight into a ticket. Optionally spins a Docker lab container so you can reproduce the bug.

Try it in 60 seconds

git clone https://github.com/Danush-Aries/cve-advisor.git
cd cve-advisor
python -m venv .venv && source .venv/bin/activate
pip install -r requirements.txt

cp .env.example backend/.env   # add ANTHROPIC_API_KEY
uvicorn backend.main:app --reload --port 8000

curl http://localhost:8000/api/cve/CVE-2021-44228 | jq .

Interactive docs: http://localhost:8000/docs.

How it works

  • NVD 2.0 client (backend/services/nvd_client.py) — async httpx, extracts CVSS v3.1 / v3.0 / v2 metrics in that order of preference. Handles missing metric keys instead of KeyError-ing.
  • Exploit-DB fan-out — hits the AJAX JSON endpoint (www.exploit-db.com/search), falls back to the search HTML if the JSON API is rate-limited.
  • AsyncAnthropic analyser — claude-opus-4-5 gets the NVD summary + PoC links + CVSS vector, returns a 3-section Markdown report (Attack Surface / Exploitability / Remediation).
  • File-based cache (7-day TTL) sits in front of both NVD and Exploit-DB — repeat lookups are free and don't burn NVD's 5 req / 30 sec limit.
  • Docker lab endpoint (POST /api/lab/build) uses docker-py to boot a sandboxed reproduction container (e.g. vulhub/log4j:2.14.1) so you can actually pop the bug you just read about.

Usage

Analyse a CVE

curl http://localhost:8000/api/cve/CVE-2021-44228

Returns structured NVD data + PoC links + a Claude-written Markdown report with Attack Surface / Exploitability / Remediation sections.

Python client

import httpx

async def analyse(cve_id: str):
    async with httpx.AsyncClient() as client:
        response = await client.get(f"http://localhost:8000/api/cve/{cve_id}")
        response.raise_for_status()
        return response.json()

Launch a sandboxed lab container

curl -X POST http://localhost:8000/api/lab/build \
  -H "Content-Type: application/json" \
  -d '{"image_name": "vulhub/log4j:2.14.1", "cve_id": "CVE-2021-44228"}'

Requires Docker daemon and the docker Python package.

Docker

docker build -t cve-advisor .
docker run -p 8000:8000 \
  -e ANTHROPIC_API_KEY=your_key \
  -e NVD_API_KEY=your_nvd_key \
  cve-advisor

Environment variables

Variable Required Description
ANTHROPIC_API_KEY Yes Anthropic API key for Claude analysis
NVD_API_KEY No NVD API key (higher rate limits; free to register)
CORS_ORIGINS No Comma-separated allowed origins (default: *)
DOCKER_HOST No Docker daemon socket (default: system default)

Stack

FastAPI + Uvicorn · httpx (async) · Anthropic Python SDK (AsyncAnthropic) · claude-opus-4-5 · Docker SDK for Python · Pydantic v2 · pytest + pytest-asyncio.

Project structure

cve-advisor/
├── backend/
│   ├── main.py                 # FastAPI app, routes
│   ├── models/cve.py           # Pydantic response model
│   └── services/
│       ├── nvd_client.py       # NVD + Exploit-DB clients
│       ├── ai_analyzer.py      # AsyncAnthropic Claude integration
│       └── lab_manager.py      # Docker lab container router
├── tests/
├── .env.example
├── Dockerfile
└── requirements.txt

Contributing

PRs welcome. New source clients (Vulners, GitHub Security Advisories, CISA KEV) go in backend/services/ and only need to return a normalised dict — the analyser prompt already handles source-agnostic evidence.

License

MIT — see LICENSE.


More from Danush


⭐ If this project helps you, star it — stars are how open-source tools get found, and every one directly supports more development.
· Found a bug? Open an issue · Want to chat? Discussions · Contribute? See CONTRIBUTING.md ·

About

AI-powered CVE advisor that analyzes code and recommends patches for known vulnerabilities

Topics

Resources

Contributing

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages