This run included 1 asset. It completed 8 checks for 1 asset.
13 problems were found, 6 of them Critical or High severity.
Start with “Vulnerable package pyyaml 5.3.1 (CVE-2020-14343 / GHSA-8q59-q68h-6hv4)”: Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.
Problems by severity
Severity describes possible impact. It is the scanner's rating where one was given, and this product's stated basis where none was.
Critical1
High5
Medium3
Low2
Informational0
Unknown2
What each check reached
One row per requested asset, one column per check in this run. An empty cell means no check of that kind was planned for that asset, which is not a result.
One row per selected asset, one column per check in this run
Asset
Checkov
Gitleaks
Grype
KICS
Semgrep
Syft
Trivy
TruffleHog
Asset 1
●Completed
●Completed
●Completed
●Completed
●Completed
●Completed
●Completed
●Completed
● Completed
◐ Partly completed
◑ Timed out
◇ Cancelled
✕ Failed
○ Not tested
No check planned
Which assets need attention
Every selected asset appears once. A no-problem result applies only to the security checks that completed.
Assets ordered by what this run found on them
Asset
What this run shows
Severity mix
Asset 1Repository
Problems found
Critical 1 · High 5 · Medium 3 · Low 2 · Unknown 2
Next step: Problems found — review this asset's highest-priority problem first.
Problems follow the report order. Severity is the scanner's rating of possible impact (this product rates it only when the scanner did not), confidence describes evidence strength, and priority is this product's recommended order. When this product places a problem lower than its severity suggests, the card says why.
13 problems · 26 original findings
Confidence: where a scanner reported no confidence of its own, this product's rating comes from an installed-version match against a published advisory range; a deterministic policy or configuration evaluation; a pattern or detector match.
By not specifying a USER, a program in the container may run as 'root'. This is a security hazard. If an attacker can control a process running as root, they may have control over the container. Ensure that the last USER in a Dockerfile is a USER other than 'root'.
Asset 1
Change the code to remove the reported unsafe pattern.
Detected a possible YAML deserialization vulnerability. `yaml.unsafe_load`, `yaml.Loader`, `yaml.CLoader`, and `yaml.UnsafeLoader` are all known to be unsafe methods of deserializing YAML. An attacker with control over the YAML input could create special YAML input that allows the attacker to run arbitrary Python code. This would allow the attacker to steal files, download and install malware, or otherwise take over the machine. Use `yaml.safe_load` or `yaml.SafeLoader` instead.
Asset 1
Change the code to remove the reported unsafe pattern.
Severity: CriticalConfidence: MediumPriority: 95Report order #1Suggested expert: Software supply-chain engineer
Grype reported a critical-severity condition on the assessed asset. Possible impact: A container or software component may expose the workload to a known weakness.
What to do next: Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.
Scanner-provided fixed version: 5.4
How to confirm the fix: Rerun Grype with the same scope after the change and confirm that source rule GHSA-8q59-q68h-6hv4 is no longer reported.
The packaged mapping catalog has no entry for this finding's rule, so its framework position is unknown, not absent.
PyYAML: incomplete fix for CVE-2020-1747 — Asset 1
Severity: CriticalConfidence: MediumPriority: 95Report order #2Suggested expert: Software supply-chain engineer
Trivy reported a critical-severity condition on the assessed asset. Possible impact: A container or software component may expose the workload to a known weakness.
What to do next: Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.
Scanner-provided fixed version: 5.4
How to confirm the fix: Rerun Trivy with the same scope after the change and confirm that source rule CVE-2020-14343 is no longer reported.
ISO/IEC 27001 2022 / A.8.8 — Technical vulnerability handling Relationship: related Why related: Evidence that an installed component is affected by a CVE is related to vulnerability handling. For an AI system, AIDEFEND separates build or deployment admission from the deployed-software remediation lifecycle; this reference does not decide which lifecycle state applies.
NIST CSF 2.0 / ID.RA-01 — Vulnerability identification and recording Relationship: related Why related: Evidence that an installed component is affected by a CVE is related to vulnerability handling. For an AI system, AIDEFEND separates build or deployment admission from the deployed-software remediation lifecycle; this reference does not decide which lifecycle state applies.
OWASP Top 10 2021 / A06:2021 — Vulnerable and Outdated Components Relationship: related Why related: Evidence that an installed component is affected by a CVE is related to vulnerability handling. For an AI system, AIDEFEND separates build or deployment admission from the deployed-software remediation lifecycle; this reference does not decide which lifecycle state applies.
OWASP Top 10 2021 / A03:2021 — Injection Relationship: related Why related: OWASP publishes A03:2021 as this set of CWEs, so a scanner-assigned CWE in the set places the result in the category.
Missing User Instruction — Asset 1
Severity: HighConfidence: HighPriority: 80Report order #3Suggested expert: Infrastructure-as-code engineer
KICS reported a high-severity condition on the assessed asset. Possible impact: Deployed infrastructure may inherit the reported insecure configuration.
What to do next: Correct the infrastructure-as-code template so redeployment does not restore the insecure setting.
How to confirm the fix: Rerun KICS with the same scope after the change and confirm that “Missing User Instruction” is no longer reported.
Official scanner references:https://docs.docker.com/engine/reference/builder/#user · https://github.com/Checkmarx/kics · https://www.kics.io/
Evidence and framework references
Selected-run source: Saved result from this run · Finding ID:finding-42c0982cc09ae3fb2a33a0a4a0585c35
Why this priority
Source severity: HIGH
Confidence derived from a deterministic policy or configuration evaluation; KICS reports no confidence of its own.
Semgrep reported a high-severity condition on the assessed asset. Possible impact: Source code or credentials may permit unauthorized access or unsafe application behavior.
What to do next: Change the code to remove the reported unsafe pattern.
How to confirm the fix: Rerun Semgrep with the same scope after the change and confirm that source rule ai-security-scanner.generic.private-key is no longer reported.
Official scanner references:https://github.com/semgrep/semgrep · https://semgrep.dev/
Evidence and framework references
Selected-run source: Saved result from this run · Finding ID:finding-6bcb745466e2a06f9c7780c5f7d946f8
ISO/IEC 27001 2022 / A.5.17 — Authentication information safeguards Relationship: related Why related: Static-analysis evidence of private-key material in current project files is related to managing credentials and protecting authentication information. AIDEFEND's static-admission coordinate applies when the selected artifact was generated or materially changed by AI.
NIST CSF 2.0 / PR.AA-01 — Identity and credential lifecycle management Relationship: related Why related: Static-analysis evidence of private-key material in current project files is related to managing credentials and protecting authentication information. AIDEFEND's static-admission coordinate applies when the selected artifact was generated or materially changed by AI.
OWASP Top 10 2021 / A07:2021 — Identification and Authentication Failures Relationship: related Why related: OWASP publishes A07:2021 as this set of CWEs, so a scanner-assigned CWE in the set places the result in the category.
Private Key detected. This is a sensitive credential and should not be hardcoded here. Instead, store this in a separate, private file. — Asset 1
Semgrep reported a high-severity condition on the assessed asset. Possible impact: Source code or credentials may permit unauthorized access or unsafe application behavior.
What to do next: Change the code to remove the reported unsafe pattern.
How to confirm the fix: Rerun Semgrep with the same scope after the change and confirm that source rule generic.secrets.security.detected-private-key.detected-private-key is no longer reported.
Official scanner references:https://github.com/semgrep/semgrep · https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures · https://semgrep.dev/
Evidence and framework references
Selected-run source: Saved result from this run · Finding ID:finding-7c9a7f23929702010047ac82dac05669
OWASP Top 10 2021 / A07:2021 — Identification and Authentication Failures Relationship: related Why related: OWASP publishes A07:2021 as this set of CWEs, so a scanner-assigned CWE in the set places the result in the category.
Identified a Private Key, which may compromise cryptographic security and sensitive data encryption. — Asset 1
Severity: UnknownConfidence: LowPriority: 20Report order #24Suggested expert: Secrets-response specialist
Gitleaks reported this condition without a severity rating. Severity is Unknown. Possible impact: Source code or credentials may permit unauthorized access or unsafe application behavior.
What to do next: Revoke and rotate the exposed credential, then remove it from the source and every retained history entry.
How to confirm the fix: Rerun Gitleaks with the same scope after the change and confirm that source rule private-key is no longer reported.
Official scanner references:https://github.com/gitleaks/gitleaks · https://gitleaks.io/
Evidence and framework references
Selected-run source: Saved result from this run · Finding ID:finding-45d01995aa1a9254e91bf21554255c6e
Why this priority
Severity is Unknown because Gitleaks did not provide a rating.
Confidence derived from a pattern or detector match; Gitleaks reports no confidence of its own.
The scanner provided no structured description, remediation, or version detail for this evidence.
Related framework references
The packaged mapping catalog has no entry for this finding's rule, so its framework position is unknown, not absent.
Potential PrivateKey secret detected — Asset 1
Severity: UnknownConfidence: LowPriority: 20Report order #25Suggested expert: Secrets-response specialist
TruffleHog reported this condition without a severity rating. Severity is Unknown. Possible impact: Source code or credentials may permit unauthorized access or unsafe application behavior.
What to do next: Revoke and rotate the exposed credential, then remove it from the source and every retained history entry.
How to confirm the fix: Rerun TruffleHog with the same scope after the change and confirm that source rule trufflehog:PrivateKey is no longer reported.
Official scanner references:https://github.com/trufflesecurity/trufflehog · https://trufflesecurity.com/trufflehog
Evidence and framework references
Selected-run source: Saved result from this run · Finding ID:finding-8a42f3d7514109d9c7f3777353324f66
Why this priority
Severity is Unknown because TruffleHog did not provide a rating.
Confidence derived from a pattern or detector match; TruffleHog reports no confidence of its own.
The scanner provided no structured description, remediation, or version detail for this evidence.
Related framework references
ISO/IEC 27001 2022 / A.5.17 — Authentication information safeguards Relationship: related Why related: Every TruffleHog result is a detected credential, so this reference covers the engine's whole detector surface rather than one detector. Evidence of a credential in source material is related to managing credentials and protecting authentication information. AIDEFEND's static-admission coordinate applies when the selected artifact was generated or materially changed by AI.
NIST CSF 2.0 / PR.AA-01 — Identity and credential lifecycle management Relationship: related Why related: Every TruffleHog result is a detected credential, so this reference covers the engine's whole detector surface rather than one detector. Evidence of a credential in source material is related to managing credentials and protecting authentication information. AIDEFEND's static-admission coordinate applies when the selected artifact was generated or materially changed by AI.
A gitleaks private-key was detected which attempts to identify hard-coded credentials. It is not recommended to store credentials in source-code, as this risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware Security Module). — Asset 1
Semgrep reported an informational-severity condition on the assessed asset. Possible impact: Source code or credentials may permit unauthorized access or unsafe application behavior.
What to do next: Change the code to remove the reported unsafe pattern.
How to confirm the fix: Rerun Semgrep with the same scope after the change and confirm that source rule generic.secrets.gitleaks.private-key.private-key is no longer reported.
Official scanner references:https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html · https://github.com/semgrep/semgrep · https://semgrep.dev/
Evidence and framework references
Selected-run source: Saved result from this run · Finding ID:finding-ec64abb3260d251530fa689d667752ea
OWASP Top 10 2021 / A07:2021 — Identification and Authentication Failures Relationship: related Why related: OWASP publishes A07:2021 as this set of CWEs, so a scanner-assigned CWE in the set places the result in the category.
A subprocess launched through a shell can allow command injection. — Asset 1
High · 5 original findings
Source code or credentials may permit unauthorized access or unsafe application behavior.
Target: Asset 1
What to do next: Change the code to remove the reported unsafe pattern.
Related checks (5)
A subprocess launched through a shell can allow command injection. — Asset 1
Semgrep reported a high-severity condition on the assessed asset. Possible impact: Source code or credentials may permit unauthorized access or unsafe application behavior.
What to do next: Change the code to remove the reported unsafe pattern.
How to confirm the fix: Rerun Semgrep with the same scope after the change and confirm that source rule ai-security-scanner.python.shell-true is no longer reported.
Official scanner references:https://github.com/semgrep/semgrep · https://semgrep.dev/
Evidence and framework references
Selected-run source: Saved result from this run · Finding ID:finding-9233fe96da156be17c0b3acc65ab3e53
ISO/IEC 27001 2022 / A.8.28 — Secure coding practices Relationship: related Why related: Static-analysis evidence that Python code invokes an operating-system shell is related to secure development and pre-execution dangerous-construct checks. AIDEFEND's AI-generated-artifact coordinate applies when the selected code was generated or materially changed by AI.
ISO/IEC 27001 2022 / A.8.29 — Security testing before acceptance Relationship: related Why related: Static-analysis evidence that Python code invokes an operating-system shell is related to secure development and pre-execution dangerous-construct checks. AIDEFEND's AI-generated-artifact coordinate applies when the selected code was generated or materially changed by AI.
NIST CSF 2.0 / PR.PS-06 — Secure software development practices Relationship: related Why related: Static-analysis evidence that Python code invokes an operating-system shell is related to secure development and pre-execution dangerous-construct checks. AIDEFEND's AI-generated-artifact coordinate applies when the selected code was generated or materially changed by AI.
OWASP Top 10 2021 / A03:2021 — Injection Relationship: related Why related: OWASP publishes A03:2021 as this set of CWEs, so a scanner-assigned CWE in the set places the result in the category.
Detected user input entering a `subprocess` call unsafely. This could result in a command injection vulnerability. An attacker could use this vulnerability to execute arbitrary commands on the host, which allows them to download malware, scan sensitive data, or run any command they wish on the server. Do not let users choose the command to run. In general, prefer to use Python API versions of system commands. If you must use subprocess, use a dictionary to allowlist a set of commands. — Asset 1
Semgrep reported a high-severity condition on the assessed asset. Possible impact: Source code or credentials may permit unauthorized access or unsafe application behavior.
What to do next: Change the code to remove the reported unsafe pattern.
How to confirm the fix: Rerun Semgrep with the same scope after the change and confirm that source rule python.flask.security.injection.subprocess-injection.subprocess-injection is no longer reported.
Official scanner references:https://github.com/semgrep/semgrep · https://semgrep.dev/ · https://semgrep.dev/docs/cheat-sheets/python-command-injection/
Evidence and framework references
Selected-run source: Saved result from this run · Finding ID:finding-dbde4e6152c0657c8f6c51e872e77f21
OWASP Top 10 2021 / A03:2021 — Injection Relationship: related Why related: OWASP publishes A03:2021 as this set of CWEs, so a scanner-assigned CWE in the set places the result in the category.
Detected subprocess function 'run' with user controlled data. A malicious actor could leverage this to perform command injection. You may consider using 'shlex.escape()'. — Asset 1
Semgrep reported a high-severity condition on the assessed asset. Possible impact: Source code or credentials may permit unauthorized access or unsafe application behavior.
What to do next: Change the code to remove the reported unsafe pattern.
How to confirm the fix: Rerun Semgrep with the same scope after the change and confirm that source rule python.lang.security.dangerous-subprocess-use.dangerous-subprocess-use is no longer reported.
OWASP Top 10 2021 / A03:2021 — Injection Relationship: related Why related: OWASP publishes A03:2021 as this set of CWEs, so a scanner-assigned CWE in the set places the result in the category.
Found 'subprocess' function 'run' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead. — Asset 1
Semgrep reported a high-severity condition on the assessed asset. Possible impact: Source code or credentials may permit unauthorized access or unsafe application behavior.
What to do next: Change the code to remove the reported unsafe pattern.
How to confirm the fix: Rerun Semgrep with the same scope after the change and confirm that source rule python.lang.security.audit.subprocess-shell-true.subprocess-shell-true is no longer reported.
Official scanner references:https://docs.python.org/3/library/subprocess.html · https://github.com/semgrep/semgrep · https://semgrep.dev/ · https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess
Evidence and framework references
Selected-run source: Saved result from this run · Finding ID:finding-76758c845f47b2b794bc0aa0676e9d88
OWASP Top 10 2021 / A03:2021 — Injection Relationship: related Why related: OWASP publishes A03:2021 as this set of CWEs, so a scanner-assigned CWE in the set places the result in the category.
Detected subprocess function 'run' without a static string. If this data can be controlled by a malicious actor, it may be an instance of command injection. Audit the use of this call to ensure it is not controllable by an external resource. You may consider using 'shlex.escape()'. — Asset 1
Semgrep reported a high-severity condition on the assessed asset. Possible impact: Source code or credentials may permit unauthorized access or unsafe application behavior.
What to do next: Change the code to remove the reported unsafe pattern.
How to confirm the fix: Rerun Semgrep with the same scope after the change and confirm that source rule python.lang.security.audit.dangerous-subprocess-use-audit.dangerous-subprocess-use-audit is no longer reported.
OWASP Top 10 2021 / A03:2021 — Injection Relationship: related Why related: OWASP publishes A03:2021 as this set of CWEs, so a scanner-assigned CWE in the set places the result in the category.
By not specifying a USER, a program in the container may run as 'root'. This is a security hazard. If an attacker can control a process running as root, they may have control over the container. Ensure that the last USER in a Dockerfile is a USER other than 'root'. — Asset 1
Semgrep reported a high-severity condition on the assessed asset. Possible impact: Source code or credentials may permit unauthorized access or unsafe application behavior.
What to do next: Change the code to remove the reported unsafe pattern.
How to confirm the fix: Rerun Semgrep with the same scope after the change and confirm that source rule dockerfile.security.missing-user.missing-user is no longer reported.
Official scanner references:https://github.com/semgrep/semgrep · https://owasp.org/Top10/A04_2021-Insecure_Design · https://semgrep.dev/
Evidence and framework references
Selected-run source: Saved result from this run · Finding ID:finding-04a8f3d410a825c304eda70abc2c03ee
OWASP Top 10 2021 / A04:2021 — Insecure Design Relationship: related Why related: OWASP publishes A04:2021 as this set of CWEs, so a scanner-assigned CWE in the set places the result in the category.
Detected a possible YAML deserialization vulnerability. `yaml.unsafe_load`, `yaml.Loader`, `yaml.CLoader`, and `yaml.UnsafeLoader` are all known to be unsafe methods of deserializing YAML. An attacker with control over the YAML input could create special YAML input that allows the attacker to run arbitrary Python code. This would allow the attacker to steal files, download and install malware, or otherwise take over the machine. Use `yaml.safe_load` or `yaml.SafeLoader` instead. — Asset 1
Semgrep reported a high-severity condition on the assessed asset. Possible impact: Source code or credentials may permit unauthorized access or unsafe application behavior.
What to do next: Change the code to remove the reported unsafe pattern.
How to confirm the fix: Rerun Semgrep with the same scope after the change and confirm that source rule python.lang.security.deserialization.avoid-pyyaml-load.avoid-pyyaml-load is no longer reported.
Official scanner references:https://github.com/semgrep/semgrep · https://github.com/yaml/pyyaml/wiki/PyYAML-yaml.load(input)-Deprecation · https://nvd.nist.gov/vuln/detail/CVE-2017-18342 · https://semgrep.dev/
Evidence and framework references
Selected-run source: Saved result from this run · Finding ID:finding-37cd6787cb9b18c748c379da63f44c13
OWASP Top 10 2021 / A08:2021 — Software and Data Integrity Failures Relationship: related Why related: OWASP publishes A08:2021 as this set of CWEs, so a scanner-assigned CWE in the set places the result in the category.
Severity: MediumConfidence: MediumPriority: 60Report order #13Suggested expert: Software supply-chain engineer
Grype reported a medium-severity condition on the assessed asset. Possible impact: A container or software component may expose the workload to a known weakness.
What to do next: Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.
Scanner-provided fixed version: 2.32.0
How to confirm the fix: Rerun Grype with the same scope after the change and confirm that source rule GHSA-9wx4-h78v-vm56 is no longer reported.
The packaged mapping catalog has no entry for this finding's rule, so its framework position is unknown, not absent.
requests: subsequent requests to the same host ignore cert verification — Asset 1
Severity: MediumConfidence: MediumPriority: 60Report order #16Suggested expert: Software supply-chain engineer
Trivy reported a medium-severity condition on the assessed asset. Possible impact: A container or software component may expose the workload to a known weakness.
What to do next: Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.
Scanner-provided fixed version: 2.32.0
How to confirm the fix: Rerun Trivy with the same scope after the change and confirm that source rule CVE-2024-35195 is no longer reported.
ISO/IEC 27001 2022 / A.8.8 — Technical vulnerability handling Relationship: related Why related: Evidence that an installed component is affected by a CVE is related to vulnerability handling. For an AI system, AIDEFEND separates build or deployment admission from the deployed-software remediation lifecycle; this reference does not decide which lifecycle state applies.
NIST CSF 2.0 / ID.RA-01 — Vulnerability identification and recording Relationship: related Why related: Evidence that an installed component is affected by a CVE is related to vulnerability handling. For an AI system, AIDEFEND separates build or deployment admission from the deployed-software remediation lifecycle; this reference does not decide which lifecycle state applies.
OWASP Top 10 2021 / A06:2021 — Vulnerable and Outdated Components Relationship: related Why related: Evidence that an installed component is affected by a CVE is related to vulnerability handling. For an AI system, AIDEFEND separates build or deployment admission from the deployed-software remediation lifecycle; this reference does not decide which lifecycle state applies.
A container or software component may expose the workload to a known weakness.
Target: Asset 1
What to do next: Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.
Related checks (2)
requests: Requests vulnerable to .netrc credentials leak via malicious URLs — Asset 1
Severity: MediumConfidence: MediumPriority: 60Report order #14Suggested expert: Software supply-chain engineer
Trivy reported a medium-severity condition on the assessed asset. Possible impact: A container or software component may expose the workload to a known weakness.
What to do next: Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.
Scanner-provided fixed version: 2.32.4
How to confirm the fix: Rerun Trivy with the same scope after the change and confirm that source rule CVE-2024-47081 is no longer reported.
ISO/IEC 27001 2022 / A.8.8 — Technical vulnerability handling Relationship: related Why related: Evidence that an installed component is affected by a CVE is related to vulnerability handling. For an AI system, AIDEFEND separates build or deployment admission from the deployed-software remediation lifecycle; this reference does not decide which lifecycle state applies.
NIST CSF 2.0 / ID.RA-01 — Vulnerability identification and recording Relationship: related Why related: Evidence that an installed component is affected by a CVE is related to vulnerability handling. For an AI system, AIDEFEND separates build or deployment admission from the deployed-software remediation lifecycle; this reference does not decide which lifecycle state applies.
OWASP Top 10 2021 / A06:2021 — Vulnerable and Outdated Components Relationship: related Why related: Evidence that an installed component is affected by a CVE is related to vulnerability handling. For an AI system, AIDEFEND separates build or deployment admission from the deployed-software remediation lifecycle; this reference does not decide which lifecycle state applies.
OWASP Top 10 2021 / A04:2021 — Insecure Design Relationship: related Why related: OWASP publishes A04:2021 as this set of CWEs, so a scanner-assigned CWE in the set places the result in the category.
Severity: MediumConfidence: MediumPriority: 60Report order #17Suggested expert: Software supply-chain engineer
Grype reported a medium-severity condition on the assessed asset. Possible impact: A container or software component may expose the workload to a known weakness.
What to do next: Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.
Scanner-provided fixed version: 2.32.4
How to confirm the fix: Rerun Grype with the same scope after the change and confirm that source rule GHSA-9hjg-9r4m-mvj7 is no longer reported.
Severity: MediumConfidence: MediumPriority: 60Report order #15Suggested expert: Software supply-chain engineer
Grype reported a medium-severity condition on the assessed asset. Possible impact: A container or software component may expose the workload to a known weakness.
What to do next: Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.
Scanner-provided fixed version: 2.33.0
How to confirm the fix: Rerun Grype with the same scope after the change and confirm that source rule GHSA-gc5v-m9x4-r6x2 is no longer reported.
The packaged mapping catalog has no entry for this finding's rule, so its framework position is unknown, not absent.
requests: Requests: Security bypass due to predictable temporary file creation — Asset 1
Severity: MediumConfidence: MediumPriority: 60Report order #18Suggested expert: Software supply-chain engineer
Trivy reported a medium-severity condition on the assessed asset. Possible impact: A container or software component may expose the workload to a known weakness.
What to do next: Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.
Scanner-provided fixed version: 2.33.0
How to confirm the fix: Rerun Trivy with the same scope after the change and confirm that source rule CVE-2026-25645 is no longer reported.
ISO/IEC 27001 2022 / A.8.8 — Technical vulnerability handling Relationship: related Why related: Evidence that an installed component is affected by a CVE is related to vulnerability handling. For an AI system, AIDEFEND separates build or deployment admission from the deployed-software remediation lifecycle; this reference does not decide which lifecycle state applies.
NIST CSF 2.0 / ID.RA-01 — Vulnerability identification and recording Relationship: related Why related: Evidence that an installed component is affected by a CVE is related to vulnerability handling. For an AI system, AIDEFEND separates build or deployment admission from the deployed-software remediation lifecycle; this reference does not decide which lifecycle state applies.
OWASP Top 10 2021 / A06:2021 — Vulnerable and Outdated Components Relationship: related Why related: Evidence that an installed component is affected by a CVE is related to vulnerability handling. For an AI system, AIDEFEND separates build or deployment admission from the deployed-software remediation lifecycle; this reference does not decide which lifecycle state applies.
OWASP Top 10 2021 / A01:2021 — Broken Access Control Relationship: related Why related: OWASP publishes A01:2021 as this set of CWEs, so a scanner-assigned CWE in the set places the result in the category.
Healthcheck Instruction Missing — Asset 1
Severity: LowConfidence: HighPriority: 35Report order #19Suggested expert: Infrastructure-as-code engineer
KICS reported a low-severity condition on the assessed asset. Possible impact: Deployed infrastructure may inherit the reported insecure configuration.
What to do next: Correct the infrastructure-as-code template so redeployment does not restore the insecure setting.
How to confirm the fix: Rerun KICS with the same scope after the change and confirm that “Healthcheck Instruction Missing” is no longer reported.
Official scanner references:https://docs.docker.com/engine/reference/builder/#healthcheck · https://github.com/Checkmarx/kics · https://www.kics.io/
Evidence and framework references
Selected-run source: Saved result from this run · Finding ID:finding-21a58716ec4c5fbd166bd9a7480bb494
Why this priority
Source severity: LOW
Confidence derived from a deterministic policy or configuration evaluation; KICS reports no confidence of its own.
Severity: LowConfidence: MediumPriority: 35Report order #20Suggested expert: Software supply-chain engineer
Grype reported a low-severity condition on the assessed asset. Possible impact: A container or software component may expose the workload to a known weakness.
What to do next: Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.
Scanner-provided fixed version: 3.1.3
How to confirm the fix: Rerun Grype with the same scope after the change and confirm that source rule GHSA-68rp-wp8r-4726 is no longer reported.
The packaged mapping catalog has no entry for this finding's rule, so its framework position is unknown, not absent.
flask: Flask: Information disclosure via improper caching of session data — Asset 1
Severity: LowConfidence: MediumPriority: 35Report order #21Suggested expert: Software supply-chain engineer
Trivy reported a low-severity condition on the assessed asset. Possible impact: A container or software component may expose the workload to a known weakness.
What to do next: Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.
Scanner-provided fixed version: 3.1.3
How to confirm the fix: Rerun Trivy with the same scope after the change and confirm that source rule CVE-2026-27205 is no longer reported.
ISO/IEC 27001 2022 / A.8.8 — Technical vulnerability handling Relationship: related Why related: Evidence that an installed component is affected by a CVE is related to vulnerability handling. For an AI system, AIDEFEND separates build or deployment admission from the deployed-software remediation lifecycle; this reference does not decide which lifecycle state applies.
NIST CSF 2.0 / ID.RA-01 — Vulnerability identification and recording Relationship: related Why related: Evidence that an installed component is affected by a CVE is related to vulnerability handling. For an AI system, AIDEFEND separates build or deployment admission from the deployed-software remediation lifecycle; this reference does not decide which lifecycle state applies.
OWASP Top 10 2021 / A06:2021 — Vulnerable and Outdated Components Relationship: related Why related: Evidence that an installed component is affected by a CVE is related to vulnerability handling. For an AI system, AIDEFEND separates build or deployment admission from the deployed-software remediation lifecycle; this reference does not decide which lifecycle state applies.
Ensure that HEALTHCHECK instructions have been added to container images — Asset 1
Severity: UnknownConfidence: HighPriority: 20Report order #22Suggested expert: Infrastructure-as-code engineer
Checkov reported this condition without a severity rating. Severity is Unknown. Possible impact: Deployed infrastructure may inherit the reported insecure configuration.
What to do next: Correct the infrastructure-as-code template so redeployment does not restore the insecure setting.
How to confirm the fix: Rerun Checkov with the same scope after the change and confirm that source rule CKV_DOCKER_2 is no longer reported.
Official scanner references:https://github.com/bridgecrewio/checkov · https://www.checkov.io/
Evidence and framework references
Selected-run source: Saved result from this run · Finding ID:finding-38e43d6117d5c77fdf7a0e58a51dcc29
Why this priority
Severity is Unknown because Checkov did not provide a rating.
Confidence derived from a deterministic policy or configuration evaluation; Checkov reports no confidence of its own.
The scanner provided no structured description, remediation, or version detail for this evidence.
Related framework references
The packaged mapping catalog has no entry for this finding's rule, so its framework position is unknown, not absent.
Ensure that a user for the container has been created — Asset 1
Severity: UnknownConfidence: HighPriority: 20Report order #23Suggested expert: Infrastructure-as-code engineer
Checkov reported this condition without a severity rating. Severity is Unknown. Possible impact: Deployed infrastructure may inherit the reported insecure configuration.
What to do next: Correct the infrastructure-as-code template so redeployment does not restore the insecure setting.
How to confirm the fix: Rerun Checkov with the same scope after the change and confirm that source rule CKV_DOCKER_3 is no longer reported.
Official scanner references:https://github.com/bridgecrewio/checkov · https://www.checkov.io/
Evidence and framework references
Selected-run source: Saved result from this run · Finding ID:finding-4eaa50ebcf31d40463549976c04636a2
Why this priority
Severity is Unknown because Checkov did not provide a rating.
Confidence derived from a deterministic policy or configuration evaluation; Checkov reports no confidence of its own.
Each reference below was reached from a finding's own rule or CWE through the packaged mapping catalog. They are navigation aids for finding the relevant control text, not a compliance result: nothing here is an audit, a certification, or a pass.
Every framework in this report and what this run shows against it
Framework
What this run shows
Controls
Findings
NIST CSF version 2.0
Related references observed
3
8
ISO/IEC 27001 version 2022
Related references observed
4
8
AIDEFEND version 1.20260805
Unknown — the context answers are incomplete
0
0
OWASP Top 10 version 2021
Related references observed
6
15
OWASP Top 10 for LLM Applications version 2025
Unknown — the context answers are incomplete
0
0
CIS Kubernetes Benchmark version 1.11
Unknown — coverage is incomplete
0
0
CIS Amazon Web Services Foundations Benchmark version 3.0.0
Unknown — coverage is incomplete
0
0
AIDEFEND version 1.20260805, OWASP Top 10 for LLM Applications version 2025 — No reference to this AI-specific framework was inferred because at least one required AI-context answer is legacy or unanswered. This remains unknown, not not-applicable.
CIS Kubernetes Benchmark version 1.11, CIS Amazon Web Services Foundations Benchmark version 3.0.0 — No related reference was observed, but coverage is incomplete or unknown. This cannot be interpreted as a passed or implemented control.
NIST CSF version 2.0
Related references observed
NIST CSF controls with an observed reference
Control
Title
Findings
Severity mix
ID.RA-01
Vulnerability identification and recording
5
Critical 1 · Medium 3 · Low 1
PR.AA-01
Identity and credential lifecycle management
2
High 1 · Unknown 1
PR.PS-06
Secure software development practices
1
High 1
ISO/IEC 27001 version 2022
Related references observed
ISO/IEC 27001 controls with an observed reference
Control
Title
Findings
Severity mix
A.5.17
Authentication information safeguards
2
High 1 · Unknown 1
A.8.8
Technical vulnerability handling
5
Critical 1 · Medium 3 · Low 1
A.8.28
Secure coding practices
1
High 1
A.8.29
Security testing before acceptance
1
High 1
OWASP Top 10 version 2021
Related references observed
OWASP Top 10 controls with an observed reference
Control
Title
Findings
Severity mix
A01:2021
Broken Access Control
1
Medium 1
A03:2021
Injection
6
Critical 1 · High 5
A04:2021
Insecure Design
2
High 1 · Medium 1
A06:2021
Vulnerable and Outdated Components
5
Critical 1 · Medium 3 · Low 1
A07:2021
Identification and Authentication Failures
3
High 2 · Informational 1
A08:2021
Software and Data Integrity Failures
1
High 1
Framework sources and attribution
NIST CSF version 2.0 — NIST Cybersecurity Framework (CSF) 2.0, National Institute of Standards and Technology. Use of NIST source material remains subject to the source publication's notices. Framework relationships and rationales in this report are project-authored navigation metadata. NIST has not reviewed or endorsed this report or integration. https://doi.org/10.6028/NIST.CSWP.29
ISO/IEC 27001 version 2022 — ISO/IEC 27001:2022 control coordinates are referenced nominatively. ISO/IEC standard content remains subject to ISO's terms; this report is not a copy of the standard. Framework relationships and rationales in this report are project-authored navigation metadata. ISO and IEC have not reviewed or endorsed this report or integration. https://www.iso.org/standard/27001
AIDEFEND version 1.20260805 — AIDEFEND AI Defense Framework, created by Edward Lee, https://aidefend.net, licensed under CC BY 4.0. Creative Commons Attribution 4.0 International: https://creativecommons.org/licenses/by/4.0/ ai-security-scanner uses a modified, project-authored six-record metadata selection from AIDEFEND 1.20260805 at pinned commit e10c1678ee49f03f8fb0c97d446ba3fbc3543655. This independent integration is not affiliated with, approved, certified, sponsored, or endorsed by AIDEFEND or its owner. https://github.com/edward-playground/aidefense-framework/blob/e10c1678ee49f03f8fb0c97d446ba3fbc3543655/data/data.json
OWASP Top 10 version 2021 — OWASP Top 10:2021, Copyright (c) 2003-2025 The OWASP Foundation, Inc., licensed under CC BY-SA 4.0. Creative Commons Attribution-ShareAlike 4.0 International: https://creativecommons.org/licenses/by-sa/4.0/ Category membership is read from the CWE sets OWASP publishes for each 2021 category; the rationales beside them are project-authored navigation metadata. The OWASP Foundation has not reviewed or endorsed this report or integration. https://owasp.org/Top10/
OWASP Top 10 for LLM Applications version 2025 — OWASP Top 10 for LLM Applications 2025, OWASP GenAI Security Project, Copyright (c) The OWASP Foundation, Inc., licensed under CC BY-SA 4.0. Creative Commons Attribution-ShareAlike 4.0 International: https://creativecommons.org/licenses/by-sa/4.0/ This report references three of the ten 2025 categories, the only ones the packaged engines produce evidence for; the rationales are project-authored navigation metadata. The OWASP Foundation and the OWASP GenAI Security Project have not reviewed or endorsed this report or integration. https://genai.owasp.org/llm-top-10/
CIS Kubernetes Benchmark version 1.11 — CIS Kubernetes Benchmark v1.11 recommendation numbers and titles are referenced nominatively; they are the coordinates kube-bench itself reports against. CIS Benchmark content remains subject to the Center for Internet Security's terms of use; this report is not a copy of the benchmark. Recommendation titles are reproduced as the pinned kube-bench image reports them. The Center for Internet Security has not reviewed or endorsed this report or integration. https://www.cisecurity.org/benchmark/kubernetes
CIS Amazon Web Services Foundations Benchmark version 3.0.0 — CIS Amazon Web Services Foundations Benchmark v3.0.0 recommendation numbers and titles are referenced nominatively. CIS Benchmark content remains subject to the Center for Internet Security's terms of use; this report is not a copy of the benchmark. The recommendation-to-check relationship is the one Prowler publishes in its own CIS 3.0 compliance file. The Center for Internet Security has not reviewed or endorsed this report or integration. https://www.cisecurity.org/benchmark/amazon_web_services
Groups are presentation metadata only. Every canonical finding, fingerprint, evidence record, and raw artifact remains independent; removing a group appends history and does not delete its members.
No active presentation groups are recorded.
Immutable grouping history
Every grouping event recorded for this case, oldest first