Skip to content

fix: report unparseable CVSS vectors instead of a missing score - #325

Draft
vibgrate-team wants to merge 1 commit into
mainfrom
cursor/cvss-vector-parse-diagnostic-15d2
Draft

vibgrate-team wants to merge 1 commit into
mainfrom
cursor/cvss-vector-parse-diagnostic-15d2

Conversation

@vibgrate-team

@vibgrate-team vibgrate-team commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Summary

vg scan --vulns treated a CVSS or severity vector it could not parse the same as an advisory that never had a score: the numeric CVSS field was left null, and nothing said the vector had failed. A real zero (every impact metric None) was also easy to confuse with that silence.

A vector that is present but does not parse now leaves the score unset and adds a warning, vibgrate/cvss-vector, on the advisory, in findings, and in SARIF. The warning names the parse failure and what to supply instead (a CVSS v3.0 or v3.1 base vector, or a qualitative severity). It does not echo the raw value, so unrelated text in that field is not copied into the report.

  • An unparseable vector is a warning, not a missing score and not zero.
  • A genuinely absent vector stays absent: no score, no warning.
  • A valid CVSS v3.0/v3.1 base vector still produces the same base score, including a real zero.

Related issues

Fixes #240

Checklist

  • pnpm test passes
  • pnpm lint is clean
  • pnpm typecheck is clean
  • Docs updated (README / DOCS / ARCHITECTURE) where behavior changed
  • Determinism preserved — identical input still produces identical graph.json / report output (content-hashed IDs, stable sorts; no time, randomness, or filesystem-order dependence)
  • No proprietary or internal references — public, Apache-2.0 content only
  • Commits use Conventional Commits and are signed off (git commit -s, DCO)

Notes for reviewers

The numeric helper cvssV3BaseScore still returns null when it cannot score a vector. Callers that need to tell a parse failure from an absent score use parseCvssV3, which is what the OSV and package-manifest advisory paths now do.

Open in Web Open in Cursor 

A severity vector that fails to parse now leaves the numeric score unset
and emits a stable warning naming the failure and what to supply instead.
An absent vector stays absent, and a valid CVSS v3 base vector still
scores as before.

Fixes #240

Signed-off-by: Cursor Agent <cursoragent@cursor.com>

Co-authored-by: vibgrate-team <vibgrate-team@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug: surface actionable errors when CVSS/severity vectors fail to parse

2 participants