Vulnder

How Vulnder works

Vulnder has two halves. Every hour it collects what's known about new vulnerabilities. When you ask, it works out what you run, matches it against that data, and ranks the results by what to fix first.

The pipeline

Vulnder's architecture Two lanes meet in the Worker. Every hour, CVE records, GitHub advisories, CISA KEV and EPSS are ingested, similar CVEs are grouped with embeddings, and the result is stored in D1. On request, your words are screened by Jev, component names are extracted by Gemma 4, resolved against the catalog in D1, and judged for fit and exposure by Jev, giving a stack link. A lockfile skips those AI steps and goes straight to the stack link. The Worker matches the stack against D1, with version checks from OSV, ranks the results, and serves the results page, JSON, Atom and badge. ON REQUEST EVERY HOUR Your words Lockfile Screen Jev Extract names Gemma 4 Resolve names → products Judge fit + exposure · Jev Stack link ?s=… in the URL CVE List GHSA CISA KEV FIRST EPSS Ingest merge · record changes Group similar CVEs embeddings · CVE text only D1 90 days · catalog catalog WORKER Match Rank OSV version checks Results · JSON · Atom · badge
Calls a model on Workers AI Plain code In your browser

Every hour: collect

  1. Fetch

    New and changed CVE records, with CISA's Vulnrichment assessments (is it exploited, is it automatable). GitHub's advisories for package names and fixed versions. CISA's Known Exploited Vulnerabilities catalog. FIRST's EPSS scores.

  2. Merge and record what changed

    One record per vulnerability, whichever source it came from. New issues, KEV additions, EPSS jumps and fix releases are kept as events, for "What changed this week" and the Atom feed.

  3. Group similar CVEs AI

    Each new CVE's title is turned into an embedding once, so CVEs in the same product that describe nearly the same flaw can be grouped. The model sees CVE text only, never anything you type. Code decides what counts as similar, at a calibrated threshold.

  4. Keep 90 days

    A vulnerability stays while it was published, or had an event, in the last 90 days, so an old CVE that lands on KEV today still shows up.

When you ask: match and rank

  1. Screen AI

    Text that reads like instructions for an AI, rather than a list of what you run, is refused: first by a phrase check, then by Jev, TypeSafe's decision model.

  2. Pick out components AI

    A model on Workers AI lists the components your text names, as structured data checked against a schema. Anything whose name isn't in your words is dropped, whether it was made up or planted.

  3. Resolve

    Names are matched to the catalog of products and packages that appear in vulnerability data. A vague name like "Cisco switches" becomes several close matches, marked with ?. Lockfiles and SBOMs start here: they're read in your browser and skip the AI steps.

  4. Judge fit and exposure AI

    When your description makes your scale or hosting clear, Jev judges how well each close match fits, so a home lab sees small-business gear before data-centre switches. It also says which components your description puts on the internet. Code acts on its answers at fixed thresholds.

  5. Match

    Your stack is matched to the vulnerability data. For packages with a version, OSV checks whether that exact version is affected.

  6. Rank

    Each result gets a priority, a score for ordering, the reasons for both and a suggested time to respond. Fix first orders your components by what upgrading each one removes.

Where AI is used, and where it isn't

AI reads and judges. Code decides. A model that ranked your risk could be wrong without you ever seeing why. A rule can be read, tested and argued with.

How results are ranked

Priorities are named after the decisions in CISA's SSVC. Evidence of exploitation always outranks a prediction, and a prediction outranks severity. With AI finding more severe bugs and attackers moving faster, that order matters more every month: why prioritising matters more now.

Within a priority, a 0–100 score puts results in order. It combines threat, impact, reachability and ransomware use. It's a heuristic, not a probability. Each result names the signal that decided its priority, lists the rest, and says what data wasn't available yet, so a quiet result reads as unknown, not safe. Response times are guidance, not deadlines. The full rules are in the README.

Use it with an AI assistant

Pasting an export into a hosted AI shares your stack with that provider. A list of what you run is useful to an attacker, so check the provider's data policy first.

Privacy

What it doesn't do