Cve Triage

Scoring rubric for prioritizing CVEs by severity, exploitability, and exposure

leonmelamud f9430f2 550 B Updated

File contents

CVE Triage Rubric

Assign priority:

Priority Criteria
P1 CVSS ≥ 9.0, or known exploited (KEV), internet-facing asset
P2 CVSS 7.0–8.9 with public PoC, or KEV on internal asset
P3 CVSS 4.0–6.9, no known exploitation
P4 CVSS < 4.0, or not applicable to our stack

Always check: is the vulnerable component actually reachable in our deployment? If not, downgrade one level and note why.

leonmelamud/agentcore-toolkit/tree/main/skills/agentcore/assets/poc-cve-verify/app/cve_triage/skills/cve-triage commit f9430f2cd9

Frequently asked questions

npx skillmds@latest add leonmelamud/cve-triage