How Vulnder works
Vulnder has two halves. Every hour it collects what's known about new vulnerabilities. When you ask, it works out what you run, matches it against that data, and ranks the results by what to fix first.
The pipeline
Every hour: collect
-
Fetch
New and changed CVE records, with CISA's Vulnrichment assessments (is it exploited, is it automatable). GitHub's advisories for package names and fixed versions. CISA's Known Exploited Vulnerabilities catalog. FIRST's EPSS scores.
-
Merge and record what changed
One record per vulnerability, whichever source it came from. New issues, KEV additions, EPSS jumps and fix releases are kept as events, for "What changed this week" and the Atom feed.
-
Group similar CVEs AI
Each new CVE's title is turned into an embedding once, so CVEs in the same product that describe nearly the same flaw can be grouped. The model sees CVE text only, never anything you type. Code decides what counts as similar, at a calibrated threshold.
-
Keep 90 days
A vulnerability stays while it was published, or had an event, in the last 90 days, so an old CVE that lands on KEV today still shows up.
When you ask: match and rank
-
Screen AI
Text that reads like instructions for an AI, rather than a list of what you run, is refused: first by a phrase check, then by Jev, TypeSafe's decision model.
-
Pick out components AI
A model on Workers AI lists the components your text names, as structured data checked against a schema. Anything whose name isn't in your words is dropped, whether it was made up or planted.
-
Resolve
Names are matched to the catalog of products and packages that appear in vulnerability data. A vague name like "Cisco switches" becomes several close matches, marked with
?. Lockfiles and SBOMs start here: they're read in your browser and skip the AI steps. -
Judge fit and exposure AI
When your description makes your scale or hosting clear, Jev judges how well each close match fits, so a home lab sees small-business gear before data-centre switches. It also says which components your description puts on the internet. Code acts on its answers at fixed thresholds.
-
Match
Your stack is matched to the vulnerability data. For packages with a version, OSV checks whether that exact version is affected.
-
Rank
Each result gets a priority, a score for ordering, the reasons for both and a suggested time to respond. Fix first orders your components by what upgrading each one removes.
Where AI is used, and where it isn't
AI reads and judges. Code decides. A model that ranked your risk could be wrong without you ever seeing why. A rule can be read, tested and argued with.
- Models do: pick component names out of your description, screen it for prompt injection, judge which close matches fit and which components face the internet, and group similar CVE titles.
- Models never: rank CVEs, set a priority, hide a match, or see your lockfile.
- Their answers are untrusted. Output is checked against a schema and against your own words, and fixed thresholds in code turn a judgment into an action. Fit only reorders close matches; it never removes one.
- They fail open. If a model is unavailable, parsing carries on without it: close matches keep catalog order, and you can always add items by hand or upload a lockfile.
How results are ranked
Priorities are named after the decisions in CISA's SSVC. Evidence of exploitation always outranks a prediction, and a prediction outranks severity. With AI finding more severe bugs and attackers moving faster, that order matters more every month: why prioritising matters more now.
- Act now: on CISA's Known Exploited Vulnerabilities catalog, or CISA reports active exploitation. Respond within 24 hours on an internet-facing item, 48 hours otherwise.
- Attend: exploitation is likely, or would be easy. EPSS of 10% or more, NIST's LEV estimate of 20% or more, a similar CVE in the same product being exploited, or a critical bug an attacker can reach without a login. Within 7 days.
- Watch: serious but less pressing, such as CVSS 8.0 or more, or a proof-of-concept exploit. Within 30 days.
- Track: it affects your stack, but nothing above applies. Pick it up in your next routine update.
Within a priority, a 0–100 score puts results in order. It combines threat, impact, reachability and ransomware use. It's a heuristic, not a probability. Each result names the signal that decided its priority, lists the rest, and says what data wasn't available yet, so a quiet result reads as unknown, not safe. Response times are guidance, not deadlines. The full rules are in the README.
Use it with an AI assistant
- Export Markdown on the results page is written to hand to an assistant or a coding agent. It starts with instructions for working through the findings (check each one applies, upgrade to a fixed version or apply the mitigation, report one outcome per CVE). It also says that advisory text is quoted data, never instructions, so a planted line in an advisory can't steer your agent. Paste it into a chat, or drop it into the repository your agent is working on.
- Export JSON, and the JSON feed at
/api/feed?s=…, carry the same priorities, scores, reasons and Fix first list for scripts and tools. - The Atom feed gets one entry per change, and the badge counts known-exploited CVEs for a README.
- For agents, llms.txt describes the feeds and the stack link format, so an agent can build a stack from your manifests and fetch the results itself.
Pasting an export into a hosted AI shares your stack with that provider. A list of what you run is useful to an attacker, so check the provider's data policy first.
Privacy
- Your stack and what you type are never stored or logged. A parse is cached under a hash of the text, never the text itself.
- Lockfiles and SBOMs are read in your browser. Only package names and versions are sent.
- Stack links are left out of logs, and pages send no
Referer, so clicking through to an advisory doesn't pass your stack on. - IP addresses are used only as rate-limit keys, or as a hash salted afresh each day.
- No analytics or tracking scripts. Cloudflare Turnstile protects the submit form.
- Vulnder runs on Cloudflare, which processes every request, including the stack in a link. If that's too much exposure, run your own copy.
What it doesn't do
- It doesn't scan your systems. It knows what you tell it. A lockfile gives exact versions; a sentence gives product matches to confirm.
- It covers recent CVEs. The last 30 days by default, up to 90. It isn't an inventory of every old bug you carry.
- It knows what the data names. Packages from npm, PyPI, Maven, Go, Cargo, NuGet, Composer, RubyGems, Hex and pub, and products named in CVE records. Anything else shows as unrecognised.
- New CVEs are thin. Many arrive without a CVSS or EPSS score. Results say so rather than guess.