CVSS Triage

100% Client-Side

CVSS v4 Triage Workspace

Parse CVSS v4 vectors, add analyst context, and generate stakeholder-ready outputs without pretending to compute official CVSS scores.

Severity vs Risk

CVSS describes inherent technical severity. It does not know your asset value, internet exposure, exploit activity, or operational consequences.

  • Use CVSS to understand the vulnerability, not to replace analyst judgment.
  • Use exposure, exploit status, and business impact to set priority.
  • Treat the score as source-provided input unless your scorer is standards-verified.

CVSS Input

Paste a CVSS v4 vector or build one with the metric controls below.

This phase supports factual parsing for CVSS v4 base metrics and the documented exploit maturity metric.

Base Metric Builder

Use the selectors to build a valid base vector without relying on memory.

Context

Priority guidance is derived from this operational context, not from CVSS alone.

Outputs

Generate analyst-facing outputs after validating the vector and reviewing context.

CVSS
No assessment generated yet

Parse a valid vector, fill the context fields, and generate outputs to populate this workspace.