# Deepinfo Score From GitHub

CVEs whose Deepinfo score comes from GitHub's CVSS metric.

Source: https://docs.deepinfo.com/reference/vulnerability/search/examples/enrichment-vdeep-metric-source/

Last updated: 2026-09-26

---
`POST https://api.deepinfo.com/v1/discovery/vulnerability-search?page_size=25`

CVEs whose Deepinfo score comes from GitHub's CVSS metric.

Example 2 of 22 in **Filters › Deepinfo Score** · [Vulnerability Search Examples](/reference/vulnerability/search/examples/) · endpoint: [Search](/reference/vulnerability/search/)

Tags: `field` `enrichment.vdeep_metric.source` · `operator` `wildcard`

`enrichment.vdeep_metric.source` is the organization that supplied it, as an e-mail address or a UUID (shown here as `user@<domain>` when it is an address), in the Deepinfo score (`enrichment.vdeep_metric`: the CVSS metric Deepinfo uses for the CVE, from the newest CVSS version it has).

`wildcard` matches the pattern `*@github.com`: `*` stands for any characters.

In the response, look at `results[].enrichment.vdeep_metric.source`.

## Request

| Parameter | In | Value |
|---|---|---|
| `page_size` | query | `25` |
| `filters.must[0].name` | body | `enrichment.vdeep_metric.source` |
| `filters.must[0].type` | body | `wildcard` |
| `filters.must[0].value` | body | `*@github.com` |

```bash
curl -X POST 'https://api.deepinfo.com/v1/discovery/vulnerability-search?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{
  "filters": {
    "must": [
      {
        "name": "enrichment.vdeep_metric.source",
        "type": "wildcard",
        "value": "*@github.com"
      }
    ]
  }
}'
```

## Response

### 200 · OK

> Shortened for this page: results: 3 of 25 shown

`Content-Type: application/json` · `ratelimit-limit: 1` · `ratelimit-remaining: 0` · `ratelimit-reset: 1` · `x-ratelimit-limit-second: 1` · `x-ratelimit-remaining-second: 0` · `deepinfo-request-id: 5f0c6a8e-1b2d-4c3e-9f4a-7b8c9d0e1f2a`

```json
{
  "page": 1,
  "page_size": 25,
  "result_count": 12005,
  "results": [
    {
      "id": "CVE-2026-85061",
      "source_identifier": "user@github.com",
      "published": "2026-09-03T21:17:23Z",
      "last_modified": "2026-09-09T21:09:13Z",
      "status": "Deferred",
      "evaluator_comment": null,
      "evaluator_solution": null,
      "evaluator_impact": null,
      "cisa_exploit_add": null,
      "cisa_action_due": null,
      "cisa_required_action": null,
      "cisa_vulnerability_name": null,
      "descriptions": [
        {
          "lang": "en",
          "value": "MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap while removeAttributes() removes attributes from the same collection, shifting indexes and skipping an adjacent dangerous attribute. An attacker who controls untrusted third-party style attribution strings or user-supplied custom attributions can supply consecutive dangerous attributes, causing an attribute such as onload or ontoggle to survive sanitization and execute when the attribution control inserts the content into innerHTML. A victim must render the affected map content for the script to execute. This issue is fixed in version 6.4.1."
        }
      ],
      "references": [
        {
          "url": "https://github.com/maplibre/maplibre-gl-js/commit/1da69f3cd913a39fa948708e01478663bf48bc27",
          "source": "user@github.com",
          "tags": null
        },
        {
          "url": "https://github.com/maplibre/maplibre-gl-js/pull/8189",
          "source": "user@github.com",
          "tags": null
        },
        {
          "url": "https://github.com/maplibre/maplibre-gl-js/releases/tag/v6.4.1",
          "source": "user@github.com",
          "tags": null
        },
        {
          "url": "https://github.com/maplibre/maplibre-gl-js/security/advisories/GHSA-jrc7-96c5-q579",
          "source": "user@github.com",
          "tags": null
        }
      ],
      "metrics": {
        "cvss_metric_v40": null,
        "cvss_metric_v31": [
          {
            "source": "user@github.com",
            "type": "Secondary",
            "cvss_data": {
              "version": "3.1",
              "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
              "attack_vector": "NETWORK",
              "attack_complexity": "LOW",
              "privileges_required": "NONE",
              "user_interaction": "NONE",
              "scope": "CHANGED",
              "confidentiality_impact": "HIGH",
              "integrity_impact": "HIGH",
              "availability_impact": "NONE",
              "base_score": 10.0,
              "base_severity": "CRITICAL",
              "exploit_code_maturity": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "temporal_severity": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "modified_attack_vector": null,
              "modified_attack_complexity": null,
              "modified_privileges_required": null,
              "modified_user_interaction": null,
              "modified_scope": null,
              "modified_confidentiality_impact": null,
              "modified_integrity_impact": null,
              "modified_availability_impact": null,
              "environmental_score": null,
              "environmental_severity": null
            },
            "exploitability_score": 3.9,
            "impact_score": 5.8
          }
        ],
        "cvss_metric_v30": null,
        "cvss_metric_v2": null
      },
      "weaknesses": [
        {
          "source": "user@github.com",
          "type": "Secondary",
          "description": [
            {
              "lang": "en",
              "value": "CWE-79"
            }
          ]
        }
      ],
      "configurations": null,
      "vendor_comments": null,
      "enrichment": {
        "cpe": null,
        "cwe": [
          {
            "id": 79,
            "owasptop10_2021": "A03 Injection",
            "name": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
            "description": "The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.",
            "capec_id": [
              63,
              85,
              209,
              588,
              591,
              592
            ],
            "scope": [
              "Access Control",
              "Availability",
              "Confidentiality",
              "Integrity"
            ],
            "impact": [
              "Bypass Protection Mechanism",
              "Execute Unauthorized Code or Commands",
              "Read Application Data"
            ],
            "detection_method": [
              "Automated Static Analysis",
              "Black Box"
            ]
          }
        ],
        "epss_score": {
          "epss": 0.00309,
          "percentile": 0.23833,
          "date": "2026-09-21"
        },
        "cisa_kev": null,
        "vdeep_metric": {
          "available_versions": [
            "3.1"
          ],
          "source": "user@github.com",
          "type": "Secondary",
          "cvss_data": {
            "version": "3.1",
            "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
            "attack_vector": "NETWORK",
            "attack_complexity": "LOW",
            "attack_requirements": null,
            "privileges_required": "NONE",
            "user_interaction": "NONE",
            "vulnerable_system_confidentiality": "HIGH",
            "vulnerable_system_integrity": "HIGH",
            "vulnerable_system_availability": "NONE",
            "subsequent_system_confidentiality": null,
            "subsequent_system_integrity": null,
            "subsequent_system_availability": null,
            "exploit_maturity": null,
            "confidentiality_requirements": null,
            "integrity_requirements": null,
            "availability_requirements": null,
            "modified_attack_vector": null,
            "modified_attack_complexity": null,
            "modified_attack_requirements": null,
            "modified_privileges_required": null,
            "modified_user_interaction": null,
            "modified_vulnerable_system_confidentiality": null,
            "modified_vulnerable_system_integrity": null,
            "modified_vulnerable_system_availability": null,
            "modified_subsequent_system_confidentiality": null,
            "modified_subsequent_system_integrity": null,
            "modified_subsequent_system_availability": null,
            "safety": null,
            "automatable": null,
            "recovery": null,
            "value_density": null,
            "vulnerability_response_effort": null,
            "provider_urgency": null,
            "base_score": 10.0,
            "base_severity": "CRITICAL"
          }
        }
      }
    },
    {
      "id": "CVE-2026-77521",
      "source_identifier": "user@github.com",
      "published": "2026-09-21T21:17:10Z",
      "last_modified": "2026-09-22T14:17:15Z",
      "status": "Deferred",
      "evaluator_comment": null,
      "evaluator_solution": null,
      "evaluator_impact": null,
      "cisa_exploit_add": null,
      "cisa_action_due": null,
      "cisa_required_action": null,
      "cisa_vulnerability_name": null,
      "descriptions": [
        {
          "lang": "en",
          "value": "MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skill, or sub-application use SandboxShellBackend, which exposes an execute shell tool without excluding it and omits execute from interrupt_on, so human approval is not required. Untrusted chat or ingested content can therefore cause command execution; source deployments with MAXKB_SANDBOX disabled run commands directly as the application user, while the official root container's string-based gosu wrapper allowed shell metacharacters to execute outside the intended sandbox. This issue is fixed in version 2.10.5-lts."
        }
      ],
      "references": [
        {
          "url": "https://github.com/1Panel-dev/MaxKB/commit/594f50f2ea80a502d1c955371ba0438b277c30ea",
          "source": "user@github.com",
          "tags": null
        },
        {
          "url": "https://github.com/1Panel-dev/MaxKB/releases/tag/v2.10.5-lts",
          "source": "user@github.com",
          "tags": null
        },
        {
          "url": "https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-f36j-f34j-h3rx",
          "source": "user@github.com",
          "tags": null
        },
        {
          "url": "https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-f36j-f34j-h3rx",
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "tags": null
        }
      ],
      "metrics": {
        "cvss_metric_v40": null,
        "cvss_metric_v31": [
          {
            "source": "user@github.com",
            "type": "Secondary",
            "cvss_data": {
              "version": "3.1",
              "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
              "attack_vector": "NETWORK",
              "attack_complexity": "LOW",
              "privileges_required": "NONE",
              "user_interaction": "NONE",
              "scope": "CHANGED",
              "confidentiality_impact": "HIGH",
              "integrity_impact": "HIGH",
              "availability_impact": "HIGH",
              "base_score": 10.0,
              "base_severity": "CRITICAL",
              "exploit_code_maturity": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "temporal_severity": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "modified_attack_vector": null,
              "modified_attack_complexity": null,
              "modified_privileges_required": null,
              "modified_user_interaction": null,
              "modified_scope": null,
              "modified_confidentiality_impact": null,
              "modified_integrity_impact": null,
              "modified_availability_impact": null,
              "environmental_score": null,
              "environmental_severity": null
            },
            "exploitability_score": 3.9,
            "impact_score": 6.0
          }
        ],
        "cvss_metric_v30": null,
        "cvss_metric_v2": null
      },
      "weaknesses": [
        {
          "source": "user@github.com",
          "type": "Secondary",
          "description": [
            {
              "lang": "en",
              "value": "CWE-78"
            },
            {
              "lang": "en",
              "value": "CWE-250"
            },
            {
              "lang": "en",
              "value": "CWE-749"
            }
          ]
        }
      ],
      "configurations": null,
      "vendor_comments": null,
      "enrichment": {
        "cpe": null,
        "cwe": [
          {
            "id": 250,
            "owasptop10_2021": null,
            "name": "Execution with Unnecessary Privileges",
            "description": "The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.",
            "capec_id": [
              69,
              104,
              470
            ],
            "scope": [
              "Access Control",
              "Availability",
              "Confidentiality",
              "Integrity"
            ],
            "impact": [
              "DoS: Crash, Exit, or Restart",
              "Execute Unauthorized Code or Commands",
              "Gain Privileges or Assume Identity",
              "Read Application Data"
            ],
            "detection_method": [
              "Architecture or Design Review",
              "Automated Static Analysis",
              "Automated Static Analysis - Binary or Bytecode",
              "Automated Static Analysis - Source Code",
              "Black Box",
              "Dynamic Analysis with Automated Results Interpretation",
              "Dynamic Analysis with Manual Results Interpretation",
              "Manual Analysis",
              "Manual Static Analysis - Binary or Bytecode",
              "Manual Static Analysis - Source Code"
            ]
          },
          {
            "id": 749,
            "owasptop10_2021": null,
            "name": "Exposed Dangerous Method or Function",
            "description": "The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.",
            "capec_id": [
              500
            ],
            "scope": [
              "Access Control",
              "Availability",
              "Confidentiality",
              "Integrity",
              "Other"
            ],
            "impact": [
              "Execute Unauthorized Code or Commands",
              "Gain Privileges or Assume Identity",
              "Modify Application Data",
              "Other",
              "Read Application Data"
            ],
            "detection_method": [
              "Automated Static Analysis"
            ]
          },
          {
            "id": 78,
            "owasptop10_2021": "A03 Injection",
            "name": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
            "description": "The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.",
            "capec_id": [
              6,
              15,
              43,
              88,
              108
            ],
            "scope": [
              "Availability",
              "Confidentiality",
              "Integrity",
              "Non-Repudiation"
            ],
            "impact": [
              "DoS: Crash, Exit, or Restart",
              "Execute Unauthorized Code or Commands",
              "Hide Activities",
              "Modify Application Data",
              "Modify Files or Directories",
              "Read Application Data",
              "Read Files or Directories"
            ],
            "detection_method": [
              "Architecture or Design Review",
              "Automated Dynamic Analysis",
              "Automated Static Analysis",
              "Automated Static Analysis - Binary or Bytecode",
              "Automated Static Analysis - Source Code",
              "Dynamic Analysis with Automated Results Interpretation",
              "Dynamic Analysis with Manual Results Interpretation",
              "Manual Static Analysis",
              "Manual Static Analysis - Source Code"
            ]
          }
        ],
        "epss_score": {
          "epss": 0.01049,
          "percentile": 0.62809,
          "date": "2026-09-23"
        },
        "cisa_kev": null,
        "vdeep_metric": {
          "available_versions": [
            "3.1"
          ],
          "source": "user@github.com",
          "type": "Secondary",
          "cvss_data": {
            "version": "3.1",
            "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "attack_vector": "NETWORK",
            "attack_complexity": "LOW",
            "attack_requirements": null,
            "privileges_required": "NONE",
            "user_interaction": "NONE",
            "vulnerable_system_confidentiality": "HIGH",
            "vulnerable_system_integrity": "HIGH",
            "vulnerable_system_availability": "HIGH",
            "subsequent_system_confidentiality": null,
            "subsequent_system_integrity": null,
            "subsequent_system_availability": null,
            "exploit_maturity": null,
            "confidentiality_requirements": null,
            "integrity_requirements": null,
            "availability_requirements": null,
            "modified_attack_vector": null,
            "modified_attack_complexity": null,
            "modified_attack_requirements": null,
            "modified_privileges_required": null,
            "modified_user_interaction": null,
            "modified_vulnerable_system_confidentiality": null,
            "modified_vulnerable_system_integrity": null,
            "modified_vulnerable_system_availability": null,
            "modified_subsequent_system_confidentiality": null,
            "modified_subsequent_system_integrity": null,
            "modified_subsequent_system_availability": null,
            "safety": null,
            "automatable": null,
            "recovery": null,
            "value_density": null,
            "vulnerability_response_effort": null,
            "provider_urgency": null,
            "base_score": 10.0,
            "base_severity": "CRITICAL"
          }
        }
      }
    },
    {
      "id": "CVE-2026-77244",
      "source_identifier": "user@github.com",
      "published": "2026-09-22T18:17:17Z",
      "last_modified": "2026-09-23T18:12:04Z",
      "status": "Awaiting Analysis",
      "evaluator_comment": null,
      "evaluator_solution": null,
      "evaluator_impact": null,
      "cisa_exploit_add": null,
      "cisa_action_due": null,
      "cisa_required_action": null,
      "cisa_vulnerability_name": null,
      "descriptions": [
        {
          "lang": "en",
          "value": "MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the HTTP transport accepts requests without a verified user identity and downstream fetcher construction falls back to the operator's globally configured Jira or Confluence credentials. A network client that can reach the MCP endpoint can invoke Atlassian tools as the operator, including read and write operations available to that account. The advisory traces the vulnerable input and processing flow through UserTokenMiddleware, AtlassianOpaqueTokenVerifier, _get_fetcher, and streamable-http, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0."
        }
      ],
      "references": [
        {
          "url": "https://github.com/sooperset/mcp-atlassian/commit/b041733473f95119dd539542a43c280737a8e460",
          "source": "user@github.com",
          "tags": null
        },
        {
          "url": "https://github.com/sooperset/mcp-atlassian/pull/1448",
          "source": "user@github.com",
          "tags": null
        },
        {
          "url": "https://github.com/sooperset/mcp-atlassian/releases/tag/v0.22.0",
          "source": "user@github.com",
          "tags": null
        },
        {
          "url": "https://github.com/sooperset/mcp-atlassian/security/advisories/GHSA-wrhw-j3f9-8vc6",
          "source": "user@github.com",
          "tags": null
        }
      ],
      "metrics": {
        "cvss_metric_v40": null,
        "cvss_metric_v31": [
          {
            "source": "user@github.com",
            "type": "Secondary",
            "cvss_data": {
              "version": "3.1",
              "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
              "attack_vector": "NETWORK",
              "attack_complexity": "LOW",
              "privileges_required": "NONE",
              "user_interaction": "NONE",
              "scope": "CHANGED",
              "confidentiality_impact": "HIGH",
              "integrity_impact": "HIGH",
              "availability_impact": "NONE",
              "base_score": 10.0,
              "base_severity": "CRITICAL",
              "exploit_code_maturity": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "temporal_severity": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "modified_attack_vector": null,
              "modified_attack_complexity": null,
              "modified_privileges_required": null,
              "modified_user_interaction": null,
              "modified_scope": null,
              "modified_confidentiality_impact": null,
              "modified_integrity_impact": null,
              "modified_availability_impact": null,
              "environmental_score": null,
              "environmental_severity": null
            },
            "exploitability_score": 3.9,
            "impact_score": 5.8
          }
        ],
        "cvss_metric_v30": null,
        "cvss_metric_v2": null
      },
      "weaknesses": [
        {
          "source": "user@github.com",
          "type": "Secondary",
          "description": [
            {
              "lang": "en",
              "value": "CWE-287"
            },
            {
              "lang": "en",
              "value": "CWE-303"
            },
            {
              "lang": "en",
              "value": "CWE-862"
            }
          ]
        }
      ],
      "configurations": null,
      "vendor_comments": null,
      "enrichment": {
        "cpe": null,
        "cwe": [
          {
            "id": 303,
            "owasptop10_2021": null,
            "name": "Incorrect Implementation of Authentication Algorithm",
            "description": "The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.",
            "capec_id": [
              90
            ],
            "scope": [
              "Access Control"
            ],
            "impact": [
              "Bypass Protection Mechanism"
            ],
            "detection_method": null
          },
          {
            "id": 862,
            "owasptop10_2021": "A01 Broken Access Control",
            "name": "Missing Authorization",
            "description": "The product does not perform an authorization check when an actor attempts to access a resource or perform an action.",
            "capec_id": [
              665
            ],
            "scope": [
              "Access Control",
              "Availability",
              "Confidentiality",
              "Integrity"
            ],
            "impact": [
              "Bypass Protection Mechanism",
              "DoS: Crash, Exit, or Restart",
              "DoS: Resource Consumption (CPU)",
              "DoS: Resource Consumption (Memory)",
              "DoS: Resource Consumption (Other)",
              "Gain Privileges or Assume Identity",
              "Modify Application Data",
              "Modify Files or Directories",
              "Read Application Data",
              "Read Files or Directories"
            ],
            "detection_method": [
              "Architecture or Design Review",
              "Automated Dynamic Analysis",
              "Automated Static Analysis",
              "Automated Static Analysis - Source Code",
              "Dynamic Analysis with Automated Results Interpretation",
              "Dynamic Analysis with Manual Results Interpretation",
              "Manual Analysis",
              "Manual Static Analysis - Binary or Bytecode",
              "Manual Static Analysis - Source Code"
            ]
          },
          {
            "id": 287,
            "owasptop10_2021": "A07 Identification and Authentication Failures",
            "name": "Improper Authentication",
            "description": "When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.",
            "capec_id": [
              22,
              57,
              94,
              114,
              115,
              151,
              194,
              593,
              633,
              650
            ],
            "scope": [
              "Access Control",
              "Availability",
              "Confidentiality",
              "Integrity"
            ],
            "impact": [
              "Execute Unauthorized Code or Commands",
              "Gain Privileges or Assume Identity",
              "Read Application Data"
            ],
            "detection_method": [
              "Architecture or Design Review",
              "Automated Static Analysis",
              "Automated Static Analysis - Source Code",
              "Dynamic Analysis with Automated Results Interpretation",
              "Dynamic Analysis with Manual Results Interpretation",
              "Manual Static Analysis",
              "Manual Static Analysis - Binary or Bytecode",
              "Manual Static Analysis - Source Code"
            ]
          }
        ],
        "epss_score": {
          "epss": 0.00495,
          "percentile": 0.41569,
          "date": "2026-09-23"
        },
        "cisa_kev": null,
        "vdeep_metric": {
          "available_versions": [
            "3.1"
          ],
          "source": "user@github.com",
          "type": "Secondary",
          "cvss_data": {
            "version": "3.1",
            "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
            "attack_vector": "NETWORK",
            "attack_complexity": "LOW",
            "attack_requirements": null,
            "privileges_required": "NONE",
            "user_interaction": "NONE",
            "vulnerable_system_confidentiality": "HIGH",
            "vulnerable_system_integrity": "HIGH",
            "vulnerable_system_availability": "NONE",
            "subsequent_system_confidentiality": null,
            "subsequent_system_integrity": null,
            "subsequent_system_availability": null,
            "exploit_maturity": null,
            "confidentiality_requirements": null,
            "integrity_requirements": null,
            "availability_requirements": null,
            "modified_attack_vector": null,
            "modified_attack_complexity": null,
            "modified_attack_requirements": null,
            "modified_privileges_required": null,
            "modified_user_interaction": null,
            "modified_vulnerable_system_confidentiality": null,
            "modified_vulnerable_system_integrity": null,
            "modified_vulnerable_system_availability": null,
            "modified_subsequent_system_confidentiality": null,
            "modified_subsequent_system_integrity": null,
            "modified_subsequent_system_availability": null,
            "safety": null,
            "automatable": null,
            "recovery": null,
            "value_density": null,
            "vulnerability_response_effort": null,
            "provider_urgency": null,
            "base_score": 10.0,
            "base_severity": "CRITICAL"
          }
        }
      }
    }
  ]
}
```

## Related Examples

- [KEV Notes That Cite a CISA Directive](/reference/vulnerability/search/examples/enrichment-cisa-kev-notes/)
- [KEV Descriptions That Mention JNDI](/reference/vulnerability/search/examples/enrichment-cisa-kev-short-description/)
- [Wildcard: A Range of CVE Ids](/reference/vulnerability/search/examples/operator-wildcard/)
- [CVSS 4.0: Scored by VulnCheck](/reference/vulnerability/search/examples/metrics-cvss-metric-v40-source/)
- [CVSS v3.1: Scored by Microsoft](/reference/vulnerability/search/examples/metrics-cvss-metric-v31-source/)
- [CVSS v3.0: Scored by HackerOne](/reference/vulnerability/search/examples/metrics-cvss-metric-v30-source/)
