{"uid":"cap_Sr3fxrJafOvT1dhlVb5_c","slug":"macaroon-network-cyber-vulnerability-risk-search-eb1926c8","name":"Macaroon Network Cyber Vulnerability Risk Search","description":"Search CVEs, CISA Known Exploited Vulnerabilities status, and GitHub Security Advisory package/ecosystem metadata in one call. Composes three separately licence-cleared sources: the NVD CVE API (CVSS scoring, descriptions), CVE Program data from cve.org (delivered via NVD), the CISA KEV catalog (CC0 1.0), and the GitHub Security Advisory Database's github-reviewed set (CC-BY-4.0), ingested only via a local git checkout of the public repository -- never the live GitHub Security Advisories API. Do","url":"https://api.macaroonnetwork.com/execute/cyber-vulnerability-risk-search-v1","method":"POST","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method","bodyType","body"],"properties":{"body":{"type":"object"},"type":{"type":"string","const":"http"},"method":{"enum":["POST","PUT","PATCH"],"type":"string"},"bodyType":{"enum":["json","form-data","text"],"type":"string"}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.003","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.003/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_bmQqo9r1Oj9kjRYV48Lq5","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.003","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Search CVEs, CISA Known Exploited Vulnerabilities status, and GitHub Security Advisory package/ecosystem metadata in a single API call, combining NVD CVSS scoring, CISA KEV catalog, and GitHub-reviewed advisories.","exampleAgentPrompt":"Can you look up CVE-2021-44228 (Log4Shell) and tell me if it's in the CISA Known Exploited Vulnerabilities catalog, what its CVSS score is, and whether there are any GitHub Security Advisory records for affected Java packages?","exampleUseCases":[{"title":"Triage critical CVE before patching","prompt":"We just heard about CVE-2023-44487 (HTTP/2 Rapid Reset). Can you pull its CVSS score, check if CISA has flagged it as actively exploited, and see if there are any GitHub advisories for affected packages?"},{"title":"Audit open source dependency for known vulns","prompt":"Before we ship this release, can you check if the Python requests package has any known CVEs or GitHub security advisories, and flag anything that shows up in the CISA KEV list?"},{"title":"Security briefing on newly disclosed vulnerability","prompt":"I saw a mention of a critical RCE in OpenSSL this morning. Can you search for recent OpenSSL CVEs, get their CVSS scores, and check which ones CISA considers actively exploited?"}],"resultDescription":"Returns structured vulnerability data combining: CVE identifiers with CVSS v3 scores and descriptions (from NVD), CISA KEV catalog status indicating whether each CVE is known to be actively exploited, and GitHub Security Advisory records with affected package names and ecosystem metadata (npm, PyPI, Maven, etc.) for the github-reviewed advisory set.","failureModes":["CVE not found in NVD — returns empty or partial results if the CVE ID is invalid or too recently published","Package/ecosystem not indexed in GitHub advisory database — returns no GitHub advisory records","CISA KEV catalog may lag real-world exploitation discoveries by days to weeks","Malformed or missing query body — returns 400-level error","Temporary upstream NVD API rate limit or downtime — may return 503 or degraded partial response","GitHub advisory data sourced from a local git checkout, so may be slightly behind the live repository"],"whenToPreferThis":"Choose this endpoint when you need a single-call cross-source vulnerability lookup that combines NVD CVSS scores, CISA active-exploitation status, and GitHub-reviewed package advisory metadata — especially useful for software supply chain security checks, dependency auditing, or CVE triage workflows where you don't want to call three separate APIs and reconcile licenses yourself. Prefer alternatives if you need real-time GitHub Security Advisories API data (this uses a local checkout), or if you need bulk/streaming vulnerability feeds rather than targeted search queries.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T00:44:44.205Z","isFirstParty":false}