CVE Risk Check in ChatGPT
CVE severity and exploit risk. The MCP server is https://cve.openkrill.app/mcp. No key. The steps below are only for ChatGPT. A call to check_cve was checked against that server on 2026-10-01.
What this server answers
Triage a security vulnerability by its CVE id: how severe it is, whether it is being exploited, and how likely exploitation is.
Ask "how bad is CVE-2021-44228?", "which of these CVEs should I patch first?" or "what did CISA add to its exploited list this month?".
CVE Risk Check reads two free public sources. The National Vulnerability Database (NVD) gives the description, the CVSS score and severity, the publication date, a link to a patch or vendor advisory when one is tagged, and whether the CISA Known Exploited Vulnerabilities (KEV) catalog lists the CVE, with CISA's due date and required action. FIRST's EPSS gives the modelled probability that the CVE is exploited in the next 30 days.
Each CVE gets a priority: "exploited" when CISA lists it, "likely" when its EPSS score is 0.1 or more, otherwise "routine", or "unknown" when EPSS could not be read. A batch of up to 10 CVEs comes back sorted with the most urgent first.
Every answer names its sources and the date the NVD record and the EPSS score are from. NVD limits requests without a key, so records are cached for a few hours; a recent change to a CVE can take that long to appear, and when NVD asks this service to slow down the answer says so and when to retry.
It looks up CVE ids. It does not scan your systems, find which packages or versions are affected (use Package Health Check for that), confirm that you are vulnerable, or tell you how to exploit anything. The ids you ask about are not stored; the only lasting record is a daily count of calls per tool.
What it can do
- Looks up a CVE's description, CVSS score and severity, and publication date from the NVD
- Shows whether the CISA Known Exploited Vulnerabilities catalog lists a CVE, with its due date and required action
- Adds the EPSS score: the modelled chance of exploitation in the next 30 days
- Gives each CVE a priority: exploited, likely or routine
- Ranks a batch of up to 10 CVEs with the most urgent first
- Lists CVEs recently added to the CISA exploited list, optionally filtered by a product word
- Links a patch or vendor advisory when NVD tags one, and names its sources and dates
Tools
check_cve, Check a CVE. Use this when the user asks how serious a CVE is, such as "how bad is CVE-2021-44228?". Pass the CVE id. Returns a priority (exploited, likely, routine or unknown), the description, CVSS score and severity, whether the CISA Known Exploited Vulnerabilities catalog lists it, the EPSS exploitation probability, a patch or advisory link when tagged, and the as_of dates. A lookup by CVE id: it does not know which software the user runs or whether they are affected.check_cves, Rank several CVEs. Use this when the user has a list of CVE ids and wants to know which to deal with first, such as "which of these CVEs should I patch first?". Pass up to 10 CVE ids. Returns each one's priority, CVSS score, CISA exploited-list status and EPSS score, most urgent first, with a count per priority. An id NVD could not be asked about in this call is marked deferred; ask for it again later. It does not know which software the user runs.list_recent_kev, List recent exploited CVEs. Use this when the user asks what CISA recently added to its Known Exploited Vulnerabilities list, such as "what exploited CVEs were added this month?". Optionally pass how many days back (up to 90), a product word to filter by, and a limit. Returns each CVE with its CISA name, the date it was added, CISA's due date and its CVSS score, newest first. The catalog lists vulnerabilities with evidence of exploitation; it is not a list of every serious CVE.
Add CVE Risk Check in ChatGPT
ChatGPT does not read a local config file. A custom MCP server is added in the product, and only after developer mode is on. These steps were checked against OpenAI's plugin connect guide and the ChatGPT MCP guide on 2026-10-01. Developer mode can be hidden by a workspace policy, so a Team or Enterprise admin may have to allow it first.
- Open ChatGPT settings, then Security and login, and turn on Developer mode.
- Open ChatGPT plugins and select the plus button.
- Enter a name such as "CVE Risk Check" and a one-line description of what you want it to answer.
- Under Connection, choose the public endpoint and paste
https://cve.openkrill.app/mcp. Include the/mcppath. Do not add a tunnel id: this server is already public. - Create the connection and review the tools ChatGPT lists. You should see
check_cve,check_cves,list_recent_kev. The feedback tools on the same server are optional and not required for the lookup. - Start a new conversation, add the connection from the tools menu, and ask: How bad is CVE-2021-44228?
No API key and no OAuth client id are required. The server answers without a login. Calls are limited per network and per day, and a limit comes back as a tool error rather than a partial answer. If the tool list is stale after a server change, open the connection and select Refresh, then start a new conversation.
The ChatGPT desktop app, Codex CLI and IDE extension share a different config. In the desktop app, open Settings, then MCP servers, choose Add server, select Streamable HTTP, and paste the same URL. In ~/.codex/config.toml the equivalent is a table named mcp_servers.cve with url = "https://cve.openkrill.app/mcp". ChatGPT on the web does not read that file. A published directory listing is also a different path: this page is the developer-mode connection, not a claim that CVE Risk Check is already in the ChatGPT directory.
Treat the server as untrusted until you have read a few answers. A remote MCP server sees the arguments the model sends. CVE Risk Check is read-only and documents what it sends onward on the privacy page.
A call checked on 2026-10-01
CVE-2021-44228 is Log4Shell, listed by CISA, so priority, CVSS and KEV can be checked against the public record. The request below was posted to https://cve.openkrill.app/mcp as tools/call. HTTP 200. Source: the CVE Risk Check server, read 2026-10-01.
{
"method": "tools/call",
"params": {
"name": "check_cve",
"arguments": {
"cve": "CVE-2021-44228"
}
}
}
- status. ok
- priority. exploited
- cve. CVE-2021-44228
- source. NVD (nvd.nist.gov, includes the CISA Known Exploited Vulnerabilities flag) and FIRST EPSS (first.org)
- notice. Priority is a triage hint, not a risk rating: exploited means CISA lists it as exploited in the wild, likely means an EPSS score of 0.1 or more, routine is anything lower. To check whether a package version is affected,
- kev name. Apache Log4j2 Remote Code Execution Vulnerability
Repeat the call yourself if you need a newer reading. Cached answers expire. A rate limit is not a result: wait and try again. Nothing in the call is a ranking, a filing, or advice.