ai-security-scanner / security report

Redacted assessment case

Selected run
0a8a64dd-2993-40d0-92c3-aa994a032acd
Last saved
2026-10-07 01:24:36 UTC
Run state
Complete
13Problems found
8Checks completed
0Partly completed
0Failed
0Timed out
0Not tested
0Coverage gaps
0Record notes

In short

This run included 1 asset. It completed 8 checks for 1 asset.

13 problems were found, 6 of them Critical or High severity.

Start with “Vulnerable package pyyaml 5.3.1 (CVE-2020-14343 / GHSA-8q59-q68h-6hv4)”: Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.

Problems by severity

Severity describes possible impact. It is the scanner's rating where one was given, and this product's stated basis where none was.

Critical1
High5
Medium3
Low2
Informational0
Unknown2

What each check reached

One row per requested asset, one column per check in this run. An empty cell means no check of that kind was planned for that asset, which is not a result.

One row per selected asset, one column per check in this run
AssetCheckovGitleaksGrypeKICSSemgrepSyftTrivyTruffleHog
Asset 1CompletedCompletedCompletedCompletedCompletedCompletedCompletedCompleted

Which assets need attention

Every selected asset appears once. A no-problem result applies only to the security checks that completed.

Assets ordered by what this run found on them
AssetWhat this run showsSeverity mix
Asset 1RepositoryProblems found

Critical 1 · High 5 · Medium 3 · Low 2 · Unknown 2

Next step: Problems found — review this asset's highest-priority problem first.

What you asked to scan

Targets

Requested checks

Limits

What was actually tested

Scan period: 2026-10-07 01:11:59 UTC to 2026-10-07 01:24:36 UTC

Every check this run started, with the targets it reached and when
CheckStateTargetsStartedFinished
Grype
Version 0.117.0 · last updated 2026-08-24
CompletedAsset 12026-10-07 01:11:59 UTC2026-10-07 01:24:24 UTC
Syft
Version 1.51.0 · last updated 2026-08-24
CompletedAsset 12026-10-07 01:11:59 UTC2026-10-07 01:24:36 UTC
Checkov
Version 3.3.13 · last updated 2026-08-24
CompletedAsset 12026-10-07 01:11:59 UTC2026-10-07 01:23:13 UTC
Trivy
Version 0.74.0 · last updated 2026-08-24
CompletedAsset 12026-10-07 01:11:59 UTC2026-10-07 01:21:55 UTC
Semgrep
Version 1.174.0 (source a0c13f3) · last updated 2026-08-24
CompletedAsset 12026-10-07 01:11:59 UTC2026-10-07 01:21:28 UTC
TruffleHog
Version 3.97.0 (source 3ab759f) · last updated 2026-08-24
CompletedAsset 12026-10-07 01:11:59 UTC2026-10-07 01:22:09 UTC
Gitleaks
Version 8.30.1 · last updated 2026-08-24
CompletedAsset 12026-10-07 01:11:59 UTC2026-10-07 01:13:30 UTC
KICS
Version 2.1.20 · last updated 2026-08-24
CompletedAsset 12026-10-07 01:11:59 UTC2026-10-07 01:22:24 UTC

What was not tested

What to do next

Before changing anything: Capture the current configuration and test its restoration path before making the change.

  1. Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix. — 5 related problems call for this kind of change; each needs its own fix. The first is Vulnerable package pyyaml (GHSA-8q59-q68h-6hv4) — Critical severity, Medium confidence — this product's rating from an installed-version match against a published advisory range
    To confirm: Rerun the same scan after the changes and confirm these problems are no longer reported. Suggested expert: Software supply-chain engineer
  2. Correct the infrastructure-as-code template so redeployment does not restore the insecure setting. — 4 related problems call for this kind of change; each needs its own fix. The first is Missing User Instruction — High severity, High confidence — this product's rating from a deterministic policy or configuration evaluation
    To confirm: Rerun the same scan after the changes and confirm these problems are no longer reported. Suggested expert: Infrastructure-as-code engineer
  3. Revoke and rotate the exposed credential, then remove it from the source and every retained history entry. — A private-key block is present in the selected source snapshot. — High severity, High confidence — engine rating: HIGH
    To confirm: Rerun Semgrep with the same scope after the change and confirm that source rule ai-security-scanner.generic.private-key is no longer reported. Suggested expert: Secrets-response specialist
  4. Change the code to remove the reported unsafe pattern. — 3 related problems call for this kind of change; each needs its own fix. The first is A subprocess launched through a shell can allow command injection. — High severity, High confidence — engine rating: HIGH
    To confirm: Rerun the same scan after the changes and confirm these problems are no longer reported. Suggested expert: Application security engineer

Problems found

Problems follow the report order. Severity is the scanner's rating of possible impact (this product rates it only when the scanner did not), confidence describes evidence strength, and priority is this product's recommended order. When this product places a problem lower than its severity suggests, the card says why.

13 problems · 26 original findings

Confidence: where a scanner reported no confidence of its own, this product's rating comes from an installed-version match against a published advisory range; a deterministic policy or configuration evaluation; a pattern or detector match.

Every problem found in this run, in report order
#SeverityProblemAssetWhat to do next
1CriticalVulnerable package pyyaml 5.3.1 (CVE-2020-14343 / GHSA-8q59-q68h-6hv4)Asset 1Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.
2HighMissing User InstructionAsset 1Correct the infrastructure-as-code template so redeployment does not restore the insecure setting.
3HighSecret found in a fileAsset 1Revoke and rotate the exposed credential, then remove it from the source and every retained history entry.
4HighA subprocess launched through a shell can allow command injection.Asset 1Change the code to remove the reported unsafe pattern.
5HighBy not specifying a USER, a program in the container may run as 'root'. This is a security hazard. If an attacker can control a process running as root, they may have control over the container. Ensure that the last USER in a Dockerfile is a USER other than 'root'.Asset 1Change the code to remove the reported unsafe pattern.
6HighDetected a possible YAML deserialization vulnerability. `yaml.unsafe_load`, `yaml.Loader`, `yaml.CLoader`, and `yaml.UnsafeLoader` are all known to be unsafe methods of deserializing YAML. An attacker with control over the YAML input could create special YAML input that allows the attacker to run arbitrary Python code. This would allow the attacker to steal files, download and install malware, or otherwise take over the machine. Use `yaml.safe_load` or `yaml.SafeLoader` instead.Asset 1Change the code to remove the reported unsafe pattern.
7MediumVulnerable package requests 2.31.0 (CVE-2024-35195 / GHSA-9wx4-h78v-vm56)Asset 1Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.
8MediumVulnerable package requests 2.31.0 (CVE-2024-47081 / GHSA-9hjg-9r4m-mvj7)Asset 1Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.
9MediumVulnerable package requests 2.31.0 (CVE-2026-25645 / GHSA-gc5v-m9x4-r6x2)Asset 1Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.
10LowHealthcheck Instruction MissingAsset 1Correct the infrastructure-as-code template so redeployment does not restore the insecure setting.
11LowVulnerable package flask 3.0.3 (CVE-2026-27205 / GHSA-68rp-wp8r-4726)Asset 1Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.
12UnknownEnsure that HEALTHCHECK instructions have been added to container imagesAsset 1Correct the infrastructure-as-code template so redeployment does not restore the insecure setting.
13UnknownEnsure that a user for the container has been createdAsset 1Correct the infrastructure-as-code template so redeployment does not restore the insecure setting.

Vulnerable package pyyaml 5.3.1 (CVE-2020-14343 / GHSA-8q59-q68h-6hv4) — Asset 1

Critical · 2 original findings

A container or software component may expose the workload to a known weakness.

Target: Asset 1

What to do next: Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.

Related checks (2)

Vulnerable package pyyaml (GHSA-8q59-q68h-6hv4) — Asset 1

Severity: CriticalConfidence: MediumPriority: 95Report order #1Suggested expert: Software supply-chain engineer

Grype reported a critical-severity condition on the assessed asset. Possible impact: A container or software component may expose the workload to a known weakness.

What to do next: Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.

Scanner-provided fixed version: 5.4

How to confirm the fix: Rerun Grype with the same scope after the change and confirm that source rule GHSA-8q59-q68h-6hv4 is no longer reported.

Official scanner references: https://bugzilla.redhat.com/show_bug.cgi?id=1860466 · https://github.com/SeldonIO/seldon-core/issues/2252 · https://github.com/advisories/GHSA-8q59-q68h-6hv4 · https://github.com/anchore/grype · https://github.com/pypa/advisory-database/tree/main/vulns/pyyaml/PYSEC-2021-142.yaml · https://github.com/yaml/pyyaml/commit/a001f2782501ad2d24986959f0239a354675f9dc · https://github.com/yaml/pyyaml/issues/420 · https://github.com/yaml/pyyaml/issues/420#issuecomment-663673966 · https://nvd.nist.gov/vuln/detail/CVE-2020-14343 · https://pypi.org/project/PyYAML · https://www.oracle.com/security-alerts/cpuapr2022.html · https://www.oracle.com/security-alerts/cpujul2022.html

Evidence and framework references

Selected-run source: Saved result from this run · Finding ID: finding-48ac084909c8440eb702267e211f0706

Why this priority

  • Source severity: Critical
  • Confidence derived from an installed-version match against a published advisory range; Grype reports no confidence of its own.

Evidence SHA-256

  • 9dd51b7ab648a007bdd218d4a7db4127878bcdfe07b7973f00bad465b9af7a16
    Evidence evidence-1629864d0413d2289bf21d2fdcb13ad8 · Check grype · Observed 2026-10-07 01:24:23 UTC
    Source rule
    GHSA-8q59-q68h-6hv4
    Evidence summary
    [redacted evidence summary]
    Evidence kind
    Package Inventory
    Engine run ID
    0b2ad9f4-1ecb-4533-8d34-9d895b4ca1d8
    Artifact ID
    70f5b723-a1c1-4b4c-9b5e-c00ebf0c008c
    Result pointer
    [redacted result pointer]
    Evidence location
    [redacted location]

    Scanner-provided details

    Scanner-provided description
    [redacted scanner-provided description]
    Scanner-provided installed version
    5.3.1
    Scanner-provided fixed version
    5.4
    Scanner-reported CVSS
    9.8 · v3.1 · scored by grype
    CVSS vector
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Scanner-reported CVSS
    9.3 · v4.0 · scored by grype
    CVSS vector
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Related framework references

  • The packaged mapping catalog has no entry for this finding's rule, so its framework position is unknown, not absent.

PyYAML: incomplete fix for CVE-2020-1747 — Asset 1

Severity: CriticalConfidence: MediumPriority: 95Report order #2Suggested expert: Software supply-chain engineer

Trivy reported a critical-severity condition on the assessed asset. Possible impact: A container or software component may expose the workload to a known weakness.

What to do next: Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.

Scanner-provided fixed version: 5.4

How to confirm the fix: Rerun Trivy with the same scope after the change and confirm that source rule CVE-2020-14343 is no longer reported.

Official scanner references: https://access.redhat.com/security/cve/CVE-2020-14343 · https://avd.aquasec.com/nvd/cve-2020-14343 · https://bugzilla.redhat.com/show_bug.cgi?id=1860466 · https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14343 · https://errata.almalinux.org/8/ALSA-2021-2583.html · https://errata.rockylinux.org/RLSA-2021:2583 · https://github.com/SeldonIO/seldon-core/issues/2252 · https://github.com/advisories/GHSA-8q59-q68h-6hv4 · https://github.com/aquasecurity/trivy · https://github.com/pypa/advisory-database/tree/main/vulns/pyyaml/PYSEC-2021-142.yaml · https://github.com/yaml/pyyaml · https://github.com/yaml/pyyaml/commit/a001f2782501ad2d24986959f0239a354675f9dc

Evidence and framework references

Selected-run source: Saved result from this run · Finding ID: finding-9a75a9380dab2ba587ded019d0dcab86

Why this priority

  • Source severity: CRITICAL
  • Confidence derived from an installed-version match against a published advisory range; Trivy reports no confidence of its own.

Evidence SHA-256

  • e7e05ad7497e646463da408c8db1f7b854fa593bcaffcc8d0f68d8f39c1516c8
    Evidence evidence-ebe6a30a1e460ace9c43173bbf917c08 · Check trivy · Observed 2026-10-07 01:21:55 UTC
    Source rule
    CVE-2020-14343
    Evidence summary
    [redacted evidence summary]
    Evidence kind
    Package Inventory
    Engine run ID
    8ff52035-7920-4792-9015-79d5ab1e589d
    Artifact ID
    7238caea-4c23-48c4-a643-61d08c1a0d03
    Result pointer
    [redacted result pointer]
    Evidence location
    [redacted location]

    Scanner-provided details

    Scanner-provided description
    [redacted scanner-provided description]
    Scanner-provided installed version
    5.3.1
    Scanner-provided fixed version
    5.4
    Scanner-assigned CWE
    CWE-20
    Scanner-reported CVSS
    9.8 · v3.1 · scored by ghsa
    CVSS vector
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Scanner-reported CVSS
    9.8 · v3.1 · scored by nvd
    CVSS vector
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Scanner-reported CVSS
    10 · v2.0 · scored by nvd
    CVSS vector
    AV:N/AC:L/Au:N/C:C/I:C/A:C
    Scanner-reported CVSS
    9.8 · v3.1 · scored by redhat
    CVSS vector
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Related framework references

  • ISO/IEC 27001 2022 / A.8.8 — Technical vulnerability handling
    Relationship: related
    Why related: Evidence that an installed component is affected by a CVE is related to vulnerability handling. For an AI system, AIDEFEND separates build or deployment admission from the deployed-software remediation lifecycle; this reference does not decide which lifecycle state applies.
  • NIST CSF 2.0 / ID.RA-01 — Vulnerability identification and recording
    Relationship: related
    Why related: Evidence that an installed component is affected by a CVE is related to vulnerability handling. For an AI system, AIDEFEND separates build or deployment admission from the deployed-software remediation lifecycle; this reference does not decide which lifecycle state applies.
  • OWASP Top 10 2021 / A06:2021 — Vulnerable and Outdated Components
    Relationship: related
    Why related: Evidence that an installed component is affected by a CVE is related to vulnerability handling. For an AI system, AIDEFEND separates build or deployment admission from the deployed-software remediation lifecycle; this reference does not decide which lifecycle state applies.
  • OWASP Top 10 2021 / A03:2021 — Injection
    Relationship: related
    Why related: OWASP publishes A03:2021 as this set of CWEs, so a scanner-assigned CWE in the set places the result in the category.

Missing User Instruction — Asset 1

Severity: HighConfidence: HighPriority: 80Report order #3Suggested expert: Infrastructure-as-code engineer

KICS reported a high-severity condition on the assessed asset. Possible impact: Deployed infrastructure may inherit the reported insecure configuration.

What to do next: Correct the infrastructure-as-code template so redeployment does not restore the insecure setting.

How to confirm the fix: Rerun KICS with the same scope after the change and confirm that “Missing User Instruction” is no longer reported.

Official scanner references: https://docs.docker.com/engine/reference/builder/#user · https://github.com/Checkmarx/kics · https://www.kics.io/

Evidence and framework references

Selected-run source: Saved result from this run · Finding ID: finding-42c0982cc09ae3fb2a33a0a4a0585c35

Why this priority

Evidence SHA-256

Related framework references

Secret found in a file — Asset 1

High · 5 original findings

Source code or credentials may permit unauthorized access or unsafe application behavior.

Target: Asset 1

What to do next: Revoke and rotate the exposed credential, then remove it from the source and every retained history entry.

Related checks (5)

A private-key block is present in the selected source snapshot. — Asset 1

Severity: HighConfidence: Highengine rating: HIGHPriority: 80Report order #4Suggested expert: Application security engineer

Semgrep reported a high-severity condition on the assessed asset. Possible impact: Source code or credentials may permit unauthorized access or unsafe application behavior.

What to do next: Change the code to remove the reported unsafe pattern.

How to confirm the fix: Rerun Semgrep with the same scope after the change and confirm that source rule ai-security-scanner.generic.private-key is no longer reported.

Official scanner references: https://github.com/semgrep/semgrep · https://semgrep.dev/

Evidence and framework references

Selected-run source: Saved result from this run · Finding ID: finding-6bcb745466e2a06f9c7780c5f7d946f8

Why this priority

  • Source severity: ERROR
  • Source confidence: HIGH

Evidence SHA-256

  • 6b33e74013bd813dcf1e4d3dea6470c2a7c32e172e992c6359773ad6dec9a67c
    Evidence evidence-878afab89652bd0b69d85a332254eb92 · Check semgrep · Observed 2026-10-07 01:21:27 UTC
    Source rule
    ai-security-scanner.generic.private-key
    Evidence summary
    [redacted evidence summary]
    Evidence kind
    Source Code
    Engine run ID
    92ed7ef7-7499-424e-b760-7f992357b07a
    Artifact ID
    cf16e70c-ca68-4e91-943c-82f8edba20e6
    Result pointer
    [redacted result pointer]
    Evidence location
    [redacted location]

    Scanner-provided details

    Scanner-assigned CWE
    CWE-798

Related framework references

  • ISO/IEC 27001 2022 / A.5.17 — Authentication information safeguards
    Relationship: related
    Why related: Static-analysis evidence of private-key material in current project files is related to managing credentials and protecting authentication information. AIDEFEND's static-admission coordinate applies when the selected artifact was generated or materially changed by AI.
  • NIST CSF 2.0 / PR.AA-01 — Identity and credential lifecycle management
    Relationship: related
    Why related: Static-analysis evidence of private-key material in current project files is related to managing credentials and protecting authentication information. AIDEFEND's static-admission coordinate applies when the selected artifact was generated or materially changed by AI.
  • OWASP Top 10 2021 / A07:2021 — Identification and Authentication Failures
    Relationship: related
    Why related: OWASP publishes A07:2021 as this set of CWEs, so a scanner-assigned CWE in the set places the result in the category.

Private Key detected. This is a sensitive credential and should not be hardcoded here. Instead, store this in a separate, private file. — Asset 1

Severity: HighConfidence: Lowengine rating: LOWPriority: 80Report order #11Suggested expert: Application security engineer

Semgrep reported a high-severity condition on the assessed asset. Possible impact: Source code or credentials may permit unauthorized access or unsafe application behavior.

What to do next: Change the code to remove the reported unsafe pattern.

How to confirm the fix: Rerun Semgrep with the same scope after the change and confirm that source rule generic.secrets.security.detected-private-key.detected-private-key is no longer reported.

Official scanner references: https://github.com/semgrep/semgrep · https://owasp.org/Top10/A07_2021-Identification_and_Authentication_Failures · https://semgrep.dev/

Evidence and framework references

Selected-run source: Saved result from this run · Finding ID: finding-7c9a7f23929702010047ac82dac05669

Why this priority

  • Source severity: ERROR
  • Source confidence: LOW

Evidence SHA-256

  • 6b33e74013bd813dcf1e4d3dea6470c2a7c32e172e992c6359773ad6dec9a67c
    Evidence evidence-e6a25292c1c9640658fff928d979b2eb · Check semgrep · Observed 2026-10-07 01:21:27 UTC
    Source rule
    generic.secrets.security.detected-private-key.detected-private-key
    Evidence summary
    [redacted evidence summary]
    Evidence kind
    Source Code
    Engine run ID
    92ed7ef7-7499-424e-b760-7f992357b07a
    Artifact ID
    cf16e70c-ca68-4e91-943c-82f8edba20e6
    Result pointer
    [redacted result pointer]
    Evidence location
    [redacted location]

    Scanner-provided details

    Scanner-assigned CWE
    CWE-798

Related framework references

  • OWASP Top 10 2021 / A07:2021 — Identification and Authentication Failures
    Relationship: related
    Why related: OWASP publishes A07:2021 as this set of CWEs, so a scanner-assigned CWE in the set places the result in the category.

Identified a Private Key, which may compromise cryptographic security and sensitive data encryption. — Asset 1

Severity: UnknownConfidence: LowPriority: 20Report order #24Suggested expert: Secrets-response specialist

Gitleaks reported this condition without a severity rating. Severity is Unknown. Possible impact: Source code or credentials may permit unauthorized access or unsafe application behavior.

What to do next: Revoke and rotate the exposed credential, then remove it from the source and every retained history entry.

How to confirm the fix: Rerun Gitleaks with the same scope after the change and confirm that source rule private-key is no longer reported.

Official scanner references: https://github.com/gitleaks/gitleaks · https://gitleaks.io/

Evidence and framework references

Selected-run source: Saved result from this run · Finding ID: finding-45d01995aa1a9254e91bf21554255c6e

Why this priority

  • Severity is Unknown because Gitleaks did not provide a rating.
  • Confidence derived from a pattern or detector match; Gitleaks reports no confidence of its own.

Evidence SHA-256

  • ec85d757312734782ce64ae1424c0427072438a778bcfaef15bfba44e793465d
    Evidence evidence-f62a91f12e4e1226ec52678e9c72c8c8 · Check gitleaks · Observed 2026-10-07 01:13:30 UTC
    Source rule
    private-key
    Evidence summary
    [redacted evidence summary]
    Evidence kind
    Source Code
    Engine run ID
    b28b74f2-e4dc-459a-8d56-ec345acdd068
    Artifact ID
    77f4c5e9-77f3-4599-917e-cc25e0a73921
    Result pointer
    [redacted result pointer]
    Redacted
    Yes
    Evidence location
    [redacted location]

    The scanner provided no structured description, remediation, or version detail for this evidence.

Related framework references

  • The packaged mapping catalog has no entry for this finding's rule, so its framework position is unknown, not absent.

Potential PrivateKey secret detected — Asset 1

Severity: UnknownConfidence: LowPriority: 20Report order #25Suggested expert: Secrets-response specialist

TruffleHog reported this condition without a severity rating. Severity is Unknown. Possible impact: Source code or credentials may permit unauthorized access or unsafe application behavior.

What to do next: Revoke and rotate the exposed credential, then remove it from the source and every retained history entry.

How to confirm the fix: Rerun TruffleHog with the same scope after the change and confirm that source rule trufflehog:PrivateKey is no longer reported.

Official scanner references: https://github.com/trufflesecurity/trufflehog · https://trufflesecurity.com/trufflehog

Evidence and framework references

Selected-run source: Saved result from this run · Finding ID: finding-8a42f3d7514109d9c7f3777353324f66

Why this priority

  • Severity is Unknown because TruffleHog did not provide a rating.
  • Confidence derived from a pattern or detector match; TruffleHog reports no confidence of its own.

Evidence SHA-256

  • 0b327aebe32b417cce42a28f0989b286406f6007501c9ec50dec9520209e604e
    Evidence evidence-5aaa6fc1707f59bfcc7a1b64963bde34 · Check trufflehog · Observed 2026-10-07 01:22:08 UTC
    Source rule
    trufflehog:PrivateKey
    Evidence summary
    [redacted evidence summary]
    Evidence kind
    Source Code
    Engine run ID
    9cdabc03-7812-4c7e-ad4c-b3421fe0f51c
    Artifact ID
    b47f67c4-4e5b-425d-bc85-96ee714ddff8
    Result pointer
    [redacted result pointer]
    Redacted
    Yes
    Evidence location
    [redacted location]

    The scanner provided no structured description, remediation, or version detail for this evidence.

Related framework references

  • ISO/IEC 27001 2022 / A.5.17 — Authentication information safeguards
    Relationship: related
    Why related: Every TruffleHog result is a detected credential, so this reference covers the engine's whole detector surface rather than one detector. Evidence of a credential in source material is related to managing credentials and protecting authentication information. AIDEFEND's static-admission coordinate applies when the selected artifact was generated or materially changed by AI.
  • NIST CSF 2.0 / PR.AA-01 — Identity and credential lifecycle management
    Relationship: related
    Why related: Every TruffleHog result is a detected credential, so this reference covers the engine's whole detector surface rather than one detector. Evidence of a credential in source material is related to managing credentials and protecting authentication information. AIDEFEND's static-admission coordinate applies when the selected artifact was generated or materially changed by AI.

A gitleaks private-key was detected which attempts to identify hard-coded credentials. It is not recommended to store credentials in source-code, as this risks secrets being leaked and used by either an internal or external malicious adversary. It is recommended to use environment variables to securely provide credentials or retrieve credentials from a secure vault or HSM (Hardware Security Module). — Asset 1

Severity: InformationalConfidence: Lowengine rating: LOWPriority: 15Report order #26Suggested expert: Application security engineer

Semgrep reported an informational-severity condition on the assessed asset. Possible impact: Source code or credentials may permit unauthorized access or unsafe application behavior.

What to do next: Change the code to remove the reported unsafe pattern.

How to confirm the fix: Rerun Semgrep with the same scope after the change and confirm that source rule generic.secrets.gitleaks.private-key.private-key is no longer reported.

Official scanner references: https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html · https://github.com/semgrep/semgrep · https://semgrep.dev/

Evidence and framework references

Selected-run source: Saved result from this run · Finding ID: finding-ec64abb3260d251530fa689d667752ea

Why this priority

  • Source severity: INFO
  • Source confidence: LOW

Evidence SHA-256

  • 6b33e74013bd813dcf1e4d3dea6470c2a7c32e172e992c6359773ad6dec9a67c
    Evidence evidence-fafbce284a22c18436e0b94510895007 · Check semgrep · Observed 2026-10-07 01:21:27 UTC
    Source rule
    generic.secrets.gitleaks.private-key.private-key
    Evidence summary
    [redacted evidence summary]
    Evidence kind
    Source Code
    Engine run ID
    92ed7ef7-7499-424e-b760-7f992357b07a
    Artifact ID
    cf16e70c-ca68-4e91-943c-82f8edba20e6
    Result pointer
    [redacted result pointer]
    Evidence location
    [redacted location]

    Scanner-provided details

    Scanner-assigned CWE
    CWE-798

Related framework references

  • OWASP Top 10 2021 / A07:2021 — Identification and Authentication Failures
    Relationship: related
    Why related: OWASP publishes A07:2021 as this set of CWEs, so a scanner-assigned CWE in the set places the result in the category.

A subprocess launched through a shell can allow command injection. — Asset 1

High · 5 original findings

Source code or credentials may permit unauthorized access or unsafe application behavior.

Target: Asset 1

What to do next: Change the code to remove the reported unsafe pattern.

Related checks (5)

A subprocess launched through a shell can allow command injection. — Asset 1

Severity: HighConfidence: Highengine rating: HIGHPriority: 80Report order #5Suggested expert: Application security engineer

Semgrep reported a high-severity condition on the assessed asset. Possible impact: Source code or credentials may permit unauthorized access or unsafe application behavior.

What to do next: Change the code to remove the reported unsafe pattern.

How to confirm the fix: Rerun Semgrep with the same scope after the change and confirm that source rule ai-security-scanner.python.shell-true is no longer reported.

Official scanner references: https://github.com/semgrep/semgrep · https://semgrep.dev/

Evidence and framework references

Selected-run source: Saved result from this run · Finding ID: finding-9233fe96da156be17c0b3acc65ab3e53

Why this priority

  • Source severity: ERROR
  • Source confidence: HIGH

Evidence SHA-256

  • 6b33e74013bd813dcf1e4d3dea6470c2a7c32e172e992c6359773ad6dec9a67c
    Evidence evidence-0ea09173c5e0ab9a332a82bf363742d2 · Check semgrep · Observed 2026-10-07 01:21:27 UTC
    Source rule
    ai-security-scanner.python.shell-true
    Evidence summary
    [redacted evidence summary]
    Evidence kind
    Source Code
    Engine run ID
    92ed7ef7-7499-424e-b760-7f992357b07a
    Artifact ID
    cf16e70c-ca68-4e91-943c-82f8edba20e6
    Result pointer
    [redacted result pointer]
    Evidence location
    [redacted location]

    Scanner-provided details

    Scanner-assigned CWE
    CWE-78

Related framework references

  • ISO/IEC 27001 2022 / A.8.28 — Secure coding practices
    Relationship: related
    Why related: Static-analysis evidence that Python code invokes an operating-system shell is related to secure development and pre-execution dangerous-construct checks. AIDEFEND's AI-generated-artifact coordinate applies when the selected code was generated or materially changed by AI.
  • ISO/IEC 27001 2022 / A.8.29 — Security testing before acceptance
    Relationship: related
    Why related: Static-analysis evidence that Python code invokes an operating-system shell is related to secure development and pre-execution dangerous-construct checks. AIDEFEND's AI-generated-artifact coordinate applies when the selected code was generated or materially changed by AI.
  • NIST CSF 2.0 / PR.PS-06 — Secure software development practices
    Relationship: related
    Why related: Static-analysis evidence that Python code invokes an operating-system shell is related to secure development and pre-execution dangerous-construct checks. AIDEFEND's AI-generated-artifact coordinate applies when the selected code was generated or materially changed by AI.
  • OWASP Top 10 2021 / A03:2021 — Injection
    Relationship: related
    Why related: OWASP publishes A03:2021 as this set of CWEs, so a scanner-assigned CWE in the set places the result in the category.

Detected user input entering a `subprocess` call unsafely. This could result in a command injection vulnerability. An attacker could use this vulnerability to execute arbitrary commands on the host, which allows them to download malware, scan sensitive data, or run any command they wish on the server. Do not let users choose the command to run. In general, prefer to use Python API versions of system commands. If you must use subprocess, use a dictionary to allowlist a set of commands. — Asset 1

Severity: HighConfidence: Highengine rating: HIGHPriority: 80Report order #6Suggested expert: Application security engineer

Semgrep reported a high-severity condition on the assessed asset. Possible impact: Source code or credentials may permit unauthorized access or unsafe application behavior.

What to do next: Change the code to remove the reported unsafe pattern.

How to confirm the fix: Rerun Semgrep with the same scope after the change and confirm that source rule python.flask.security.injection.subprocess-injection.subprocess-injection is no longer reported.

Official scanner references: https://github.com/semgrep/semgrep · https://semgrep.dev/ · https://semgrep.dev/docs/cheat-sheets/python-command-injection/

Evidence and framework references

Selected-run source: Saved result from this run · Finding ID: finding-dbde4e6152c0657c8f6c51e872e77f21

Why this priority

  • Source severity: ERROR
  • Source confidence: HIGH

Evidence SHA-256

  • 6b33e74013bd813dcf1e4d3dea6470c2a7c32e172e992c6359773ad6dec9a67c
    Evidence evidence-5d84f057ae1770729875b9fdc74583f0 · Check semgrep · Observed 2026-10-07 01:21:27 UTC
    Source rule
    python.flask.security.injection.subprocess-injection.subprocess-injection
    Evidence summary
    [redacted evidence summary]
    Evidence kind
    Source Code
    Engine run ID
    92ed7ef7-7499-424e-b760-7f992357b07a
    Artifact ID
    cf16e70c-ca68-4e91-943c-82f8edba20e6
    Result pointer
    [redacted result pointer]
    Evidence location
    [redacted location]

    Scanner-provided details

    Scanner-assigned CWE
    CWE-78

Related framework references

  • OWASP Top 10 2021 / A03:2021 — Injection
    Relationship: related
    Why related: OWASP publishes A03:2021 as this set of CWEs, so a scanner-assigned CWE in the set places the result in the category.

Detected subprocess function 'run' with user controlled data. A malicious actor could leverage this to perform command injection. You may consider using 'shlex.escape()'. — Asset 1

Severity: HighConfidence: Mediumengine rating: MEDIUMPriority: 80Report order #8Suggested expert: Application security engineer

Semgrep reported a high-severity condition on the assessed asset. Possible impact: Source code or credentials may permit unauthorized access or unsafe application behavior.

What to do next: Change the code to remove the reported unsafe pattern.

How to confirm the fix: Rerun Semgrep with the same scope after the change and confirm that source rule python.lang.security.dangerous-subprocess-use.dangerous-subprocess-use is no longer reported.

Official scanner references: https://docs.python.org/3/library/shlex.html · https://docs.python.org/3/library/subprocess.html · https://github.com/semgrep/semgrep · https://semgrep.dev/ · https://semgrep.dev/docs/cheat-sheets/python-command-injection/ · https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess

Evidence and framework references

Selected-run source: Saved result from this run · Finding ID: finding-2413a2b13e71797a9f31f65191ca0a1a

Why this priority

  • Source severity: ERROR
  • Source confidence: MEDIUM

Evidence SHA-256

  • 6b33e74013bd813dcf1e4d3dea6470c2a7c32e172e992c6359773ad6dec9a67c
    Evidence evidence-fbf65b30eb2b0a538b72a13ad3bb9a90 · Check semgrep · Observed 2026-10-07 01:21:27 UTC
    Source rule
    python.lang.security.dangerous-subprocess-use.dangerous-subprocess-use
    Evidence summary
    [redacted evidence summary]
    Evidence kind
    Source Code
    Engine run ID
    92ed7ef7-7499-424e-b760-7f992357b07a
    Artifact ID
    cf16e70c-ca68-4e91-943c-82f8edba20e6
    Result pointer
    [redacted result pointer]
    Evidence location
    [redacted location]

    Scanner-provided details

    Scanner-assigned CWE
    CWE-78

Related framework references

  • OWASP Top 10 2021 / A03:2021 — Injection
    Relationship: related
    Why related: OWASP publishes A03:2021 as this set of CWEs, so a scanner-assigned CWE in the set places the result in the category.

Found 'subprocess' function 'run' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead. — Asset 1

Severity: HighConfidence: Mediumengine rating: MEDIUMPriority: 80Report order #10Suggested expert: Application security engineer

Semgrep reported a high-severity condition on the assessed asset. Possible impact: Source code or credentials may permit unauthorized access or unsafe application behavior.

What to do next: Change the code to remove the reported unsafe pattern.

Scanner-provided remediation: [redacted scanner-provided remediation]

How to confirm the fix: Rerun Semgrep with the same scope after the change and confirm that source rule python.lang.security.audit.subprocess-shell-true.subprocess-shell-true is no longer reported.

Official scanner references: https://docs.python.org/3/library/subprocess.html · https://github.com/semgrep/semgrep · https://semgrep.dev/ · https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess

Evidence and framework references

Selected-run source: Saved result from this run · Finding ID: finding-76758c845f47b2b794bc0aa0676e9d88

Why this priority

  • Source severity: ERROR
  • Source confidence: MEDIUM

Evidence SHA-256

  • 6b33e74013bd813dcf1e4d3dea6470c2a7c32e172e992c6359773ad6dec9a67c
    Evidence evidence-4d1b7983e9dde79d890632d3e1ba257d · Check semgrep · Observed 2026-10-07 01:21:27 UTC
    Source rule
    python.lang.security.audit.subprocess-shell-true.subprocess-shell-true
    Evidence summary
    [redacted evidence summary]
    Evidence kind
    Source Code
    Engine run ID
    92ed7ef7-7499-424e-b760-7f992357b07a
    Artifact ID
    cf16e70c-ca68-4e91-943c-82f8edba20e6
    Result pointer
    [redacted result pointer]
    Evidence location
    [redacted location]

    Scanner-provided details

    Scanner-provided remediation
    [redacted scanner-provided remediation]
    Scanner-assigned CWE
    CWE-78

Related framework references

  • OWASP Top 10 2021 / A03:2021 — Injection
    Relationship: related
    Why related: OWASP publishes A03:2021 as this set of CWEs, so a scanner-assigned CWE in the set places the result in the category.

Detected subprocess function 'run' without a static string. If this data can be controlled by a malicious actor, it may be an instance of command injection. Audit the use of this call to ensure it is not controllable by an external resource. You may consider using 'shlex.escape()'. — Asset 1

Severity: HighConfidence: Lowengine rating: LOWPriority: 80Report order #12Suggested expert: Application security engineer

Semgrep reported a high-severity condition on the assessed asset. Possible impact: Source code or credentials may permit unauthorized access or unsafe application behavior.

What to do next: Change the code to remove the reported unsafe pattern.

How to confirm the fix: Rerun Semgrep with the same scope after the change and confirm that source rule python.lang.security.audit.dangerous-subprocess-use-audit.dangerous-subprocess-use-audit is no longer reported.

Official scanner references: https://docs.python.org/3/library/shlex.html · https://docs.python.org/3/library/subprocess.html · https://github.com/semgrep/semgrep · https://semgrep.dev/ · https://semgrep.dev/docs/cheat-sheets/python-command-injection/ · https://stackoverflow.com/questions/3172470/actual-meaning-of-shell-true-in-subprocess

Evidence and framework references

Selected-run source: Saved result from this run · Finding ID: finding-e39cac9a3afac5c8c9e5d3318c62fd35

Why this priority

  • Source severity: ERROR
  • Source confidence: LOW

Evidence SHA-256

  • 6b33e74013bd813dcf1e4d3dea6470c2a7c32e172e992c6359773ad6dec9a67c
    Evidence evidence-7ad1d1aac83a6a6b2303c0524074a115 · Check semgrep · Observed 2026-10-07 01:21:27 UTC
    Source rule
    python.lang.security.audit.dangerous-subprocess-use-audit.dangerous-subprocess-use-audit
    Evidence summary
    [redacted evidence summary]
    Evidence kind
    Source Code
    Engine run ID
    92ed7ef7-7499-424e-b760-7f992357b07a
    Artifact ID
    cf16e70c-ca68-4e91-943c-82f8edba20e6
    Result pointer
    [redacted result pointer]
    Evidence location
    [redacted location]

    Scanner-provided details

    Scanner-assigned CWE
    CWE-78

Related framework references

  • OWASP Top 10 2021 / A03:2021 — Injection
    Relationship: related
    Why related: OWASP publishes A03:2021 as this set of CWEs, so a scanner-assigned CWE in the set places the result in the category.

By not specifying a USER, a program in the container may run as 'root'. This is a security hazard. If an attacker can control a process running as root, they may have control over the container. Ensure that the last USER in a Dockerfile is a USER other than 'root'. — Asset 1

Severity: HighConfidence: Mediumengine rating: MEDIUMPriority: 80Report order #7Suggested expert: Application security engineer

Semgrep reported a high-severity condition on the assessed asset. Possible impact: Source code or credentials may permit unauthorized access or unsafe application behavior.

What to do next: Change the code to remove the reported unsafe pattern.

Scanner-provided remediation: [redacted scanner-provided remediation]

How to confirm the fix: Rerun Semgrep with the same scope after the change and confirm that source rule dockerfile.security.missing-user.missing-user is no longer reported.

Official scanner references: https://github.com/semgrep/semgrep · https://owasp.org/Top10/A04_2021-Insecure_Design · https://semgrep.dev/

Evidence and framework references

Selected-run source: Saved result from this run · Finding ID: finding-04a8f3d410a825c304eda70abc2c03ee

Why this priority

Evidence SHA-256

Related framework references

Detected a possible YAML deserialization vulnerability. `yaml.unsafe_load`, `yaml.Loader`, `yaml.CLoader`, and `yaml.UnsafeLoader` are all known to be unsafe methods of deserializing YAML. An attacker with control over the YAML input could create special YAML input that allows the attacker to run arbitrary Python code. This would allow the attacker to steal files, download and install malware, or otherwise take over the machine. Use `yaml.safe_load` or `yaml.SafeLoader` instead. — Asset 1

Severity: HighConfidence: Mediumengine rating: MEDIUMPriority: 80Report order #9Suggested expert: Application security engineer

Semgrep reported a high-severity condition on the assessed asset. Possible impact: Source code or credentials may permit unauthorized access or unsafe application behavior.

What to do next: Change the code to remove the reported unsafe pattern.

Scanner-provided remediation: [redacted scanner-provided remediation]

How to confirm the fix: Rerun Semgrep with the same scope after the change and confirm that source rule python.lang.security.deserialization.avoid-pyyaml-load.avoid-pyyaml-load is no longer reported.

Official scanner references: https://github.com/semgrep/semgrep · https://github.com/yaml/pyyaml/wiki/PyYAML-yaml.load(input)-Deprecation · https://nvd.nist.gov/vuln/detail/CVE-2017-18342 · https://semgrep.dev/

Evidence and framework references

Selected-run source: Saved result from this run · Finding ID: finding-37cd6787cb9b18c748c379da63f44c13

Why this priority

Evidence SHA-256

Related framework references

Vulnerable package requests 2.31.0 (CVE-2024-35195 / GHSA-9wx4-h78v-vm56) — Asset 1

Medium · 2 original findings

A container or software component may expose the workload to a known weakness.

Target: Asset 1

What to do next: Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.

Related checks (2)

Vulnerable package requests (GHSA-9wx4-h78v-vm56) — Asset 1

Severity: MediumConfidence: MediumPriority: 60Report order #13Suggested expert: Software supply-chain engineer

Grype reported a medium-severity condition on the assessed asset. Possible impact: A container or software component may expose the workload to a known weakness.

What to do next: Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.

Scanner-provided fixed version: 2.32.0

How to confirm the fix: Rerun Grype with the same scope after the change and confirm that source rule GHSA-9wx4-h78v-vm56 is no longer reported.

Official scanner references: https://github.com/advisories/GHSA-9wx4-h78v-vm56 · https://github.com/anchore/grype · https://github.com/psf/requests/commit/a58d7f2ffb4d00b46dca2d70a3932a0b37e22fac · https://github.com/psf/requests/pull/6655 · https://github.com/psf/requests/security/advisories/GHSA-9wx4-h78v-vm56 · https://nvd.nist.gov/vuln/detail/CVE-2024-35195

Evidence and framework references

Selected-run source: Saved result from this run · Finding ID: finding-5b53f827c1a255e6cc6b436c74593288

Why this priority

  • Source severity: Medium
  • Confidence derived from an installed-version match against a published advisory range; Grype reports no confidence of its own.

Evidence SHA-256

  • 9dd51b7ab648a007bdd218d4a7db4127878bcdfe07b7973f00bad465b9af7a16
    Evidence evidence-1b7a1e28389a3a9b4329ac95380fcc0b · Check grype · Observed 2026-10-07 01:24:23 UTC
    Source rule
    GHSA-9wx4-h78v-vm56
    Evidence summary
    [redacted evidence summary]
    Evidence kind
    Package Inventory
    Engine run ID
    0b2ad9f4-1ecb-4533-8d34-9d895b4ca1d8
    Artifact ID
    70f5b723-a1c1-4b4c-9b5e-c00ebf0c008c
    Result pointer
    [redacted result pointer]
    Evidence location
    [redacted location]

    Scanner-provided details

    Scanner-provided description
    [redacted scanner-provided description]
    Scanner-provided installed version
    2.31.0
    Scanner-provided fixed version
    2.32.0
    Scanner-reported CVSS
    5.6 · v3.1 · scored by grype
    CVSS vector
    CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N

Related framework references

  • The packaged mapping catalog has no entry for this finding's rule, so its framework position is unknown, not absent.

requests: subsequent requests to the same host ignore cert verification — Asset 1

Severity: MediumConfidence: MediumPriority: 60Report order #16Suggested expert: Software supply-chain engineer

Trivy reported a medium-severity condition on the assessed asset. Possible impact: A container or software component may expose the workload to a known weakness.

What to do next: Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.

Scanner-provided fixed version: 2.32.0

How to confirm the fix: Rerun Trivy with the same scope after the change and confirm that source rule CVE-2024-35195 is no longer reported.

Official scanner references: https://access.redhat.com/errata/RHSA-2025:0012 · https://access.redhat.com/errata/RHSA-2025:7049 · https://access.redhat.com/security/cve/CVE-2024-35195 · https://avd.aquasec.com/nvd/cve-2024-35195 · https://bugzilla.redhat.com/2282114 · https://bugzilla.redhat.com/show_bug.cgi?id=2282114 · https://creativecommons.org/licenses/by/4.0/ · https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35195 · https://errata.almalinux.org/8/ALSA-2025-0012.html · https://errata.rockylinux.org/RLSA-2025:7049 · https://github.com/aquasecurity/trivy · https://github.com/psf/requests

Evidence and framework references

Selected-run source: Saved result from this run · Finding ID: finding-86fc7db742db356b157deae422f8338a

Why this priority

  • Source severity: MEDIUM
  • Confidence derived from an installed-version match against a published advisory range; Trivy reports no confidence of its own.

Evidence SHA-256

  • e7e05ad7497e646463da408c8db1f7b854fa593bcaffcc8d0f68d8f39c1516c8
    Evidence evidence-87b00184b15270e5cbbd7da531f51794 · Check trivy · Observed 2026-10-07 01:21:55 UTC
    Source rule
    CVE-2024-35195
    Evidence summary
    [redacted evidence summary]
    Evidence kind
    Package Inventory
    Engine run ID
    8ff52035-7920-4792-9015-79d5ab1e589d
    Artifact ID
    7238caea-4c23-48c4-a643-61d08c1a0d03
    Result pointer
    [redacted result pointer]
    Evidence location
    [redacted location]

    Scanner-provided details

    Scanner-provided description
    [redacted scanner-provided description]
    Scanner-provided installed version
    2.31.0
    Scanner-provided fixed version
    2.32.0
    Scanner-assigned CWE
    CWE-670
    Scanner-reported CVSS
    5.6 · v3.1 · scored by ghsa
    CVSS vector
    CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N
    Scanner-reported CVSS
    5.6 · v3.1 · scored by redhat
    CVSS vector
    CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N

Related framework references

  • ISO/IEC 27001 2022 / A.8.8 — Technical vulnerability handling
    Relationship: related
    Why related: Evidence that an installed component is affected by a CVE is related to vulnerability handling. For an AI system, AIDEFEND separates build or deployment admission from the deployed-software remediation lifecycle; this reference does not decide which lifecycle state applies.
  • NIST CSF 2.0 / ID.RA-01 — Vulnerability identification and recording
    Relationship: related
    Why related: Evidence that an installed component is affected by a CVE is related to vulnerability handling. For an AI system, AIDEFEND separates build or deployment admission from the deployed-software remediation lifecycle; this reference does not decide which lifecycle state applies.
  • OWASP Top 10 2021 / A06:2021 — Vulnerable and Outdated Components
    Relationship: related
    Why related: Evidence that an installed component is affected by a CVE is related to vulnerability handling. For an AI system, AIDEFEND separates build or deployment admission from the deployed-software remediation lifecycle; this reference does not decide which lifecycle state applies.

Vulnerable package requests 2.31.0 (CVE-2024-47081 / GHSA-9hjg-9r4m-mvj7) — Asset 1

Medium · 2 original findings

A container or software component may expose the workload to a known weakness.

Target: Asset 1

What to do next: Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.

Related checks (2)

requests: Requests vulnerable to .netrc credentials leak via malicious URLs — Asset 1

Severity: MediumConfidence: MediumPriority: 60Report order #14Suggested expert: Software supply-chain engineer

Trivy reported a medium-severity condition on the assessed asset. Possible impact: A container or software component may expose the workload to a known weakness.

What to do next: Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.

Scanner-provided fixed version: 2.32.4

How to confirm the fix: Rerun Trivy with the same scope after the change and confirm that source rule CVE-2024-47081 is no longer reported.

Official scanner references: https://access.redhat.com/errata/RHSA-2025:12519 · https://access.redhat.com/errata/RHSA-2025:14999 · https://access.redhat.com/security/cve/CVE-2024-47081 · https://avd.aquasec.com/nvd/cve-2024-47081 · https://bugzilla.redhat.com/2371272 · https://bugzilla.redhat.com/show_bug.cgi?id=2371272 · https://creativecommons.org/licenses/by/4.0/ · https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-47081 · https://errata.almalinux.org/8/ALSA-2025-14999.html · https://errata.rockylinux.org/RLSA-2025:12519 · https://github.com/aquasecurity/trivy · https://github.com/psf/requests

Evidence and framework references

Selected-run source: Saved result from this run · Finding ID: finding-6bfac04ddf36753a1953d3df50d9dbe5

Why this priority

  • Source severity: MEDIUM
  • Confidence derived from an installed-version match against a published advisory range; Trivy reports no confidence of its own.

Evidence SHA-256

  • e7e05ad7497e646463da408c8db1f7b854fa593bcaffcc8d0f68d8f39c1516c8
    Evidence evidence-701cb79a90f519a52e381285ed59fa3c · Check trivy · Observed 2026-10-07 01:21:55 UTC
    Source rule
    CVE-2024-47081
    Evidence summary
    [redacted evidence summary]
    Evidence kind
    Package Inventory
    Engine run ID
    8ff52035-7920-4792-9015-79d5ab1e589d
    Artifact ID
    7238caea-4c23-48c4-a643-61d08c1a0d03
    Result pointer
    [redacted result pointer]
    Evidence location
    [redacted location]

    Scanner-provided details

    Scanner-provided description
    [redacted scanner-provided description]
    Scanner-provided installed version
    2.31.0
    Scanner-provided fixed version
    2.32.4
    Scanner-assigned CWE
    CWE-522
    Scanner-reported CVSS
    5.3 · v3.1 · scored by ghsa
    CVSS vector
    CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
    Scanner-reported CVSS
    5.3 · v3.1 · scored by redhat
    CVSS vector
    CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

Related framework references

  • ISO/IEC 27001 2022 / A.8.8 — Technical vulnerability handling
    Relationship: related
    Why related: Evidence that an installed component is affected by a CVE is related to vulnerability handling. For an AI system, AIDEFEND separates build or deployment admission from the deployed-software remediation lifecycle; this reference does not decide which lifecycle state applies.
  • NIST CSF 2.0 / ID.RA-01 — Vulnerability identification and recording
    Relationship: related
    Why related: Evidence that an installed component is affected by a CVE is related to vulnerability handling. For an AI system, AIDEFEND separates build or deployment admission from the deployed-software remediation lifecycle; this reference does not decide which lifecycle state applies.
  • OWASP Top 10 2021 / A06:2021 — Vulnerable and Outdated Components
    Relationship: related
    Why related: Evidence that an installed component is affected by a CVE is related to vulnerability handling. For an AI system, AIDEFEND separates build or deployment admission from the deployed-software remediation lifecycle; this reference does not decide which lifecycle state applies.
  • OWASP Top 10 2021 / A04:2021 — Insecure Design
    Relationship: related
    Why related: OWASP publishes A04:2021 as this set of CWEs, so a scanner-assigned CWE in the set places the result in the category.

Vulnerable package requests (GHSA-9hjg-9r4m-mvj7) — Asset 1

Severity: MediumConfidence: MediumPriority: 60Report order #17Suggested expert: Software supply-chain engineer

Grype reported a medium-severity condition on the assessed asset. Possible impact: A container or software component may expose the workload to a known weakness.

What to do next: Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.

Scanner-provided fixed version: 2.32.4

How to confirm the fix: Rerun Grype with the same scope after the change and confirm that source rule GHSA-9hjg-9r4m-mvj7 is no longer reported.

Official scanner references: https://github.com/advisories/GHSA-9hjg-9r4m-mvj7 · https://github.com/anchore/grype · https://github.com/psf/requests/commit/96ba401c1296ab1dda74a2365ef36d88f7d144ef · https://github.com/psf/requests/pull/6965 · https://github.com/psf/requests/security/advisories/GHSA-9hjg-9r4m-mvj7 · https://nvd.nist.gov/vuln/detail/CVE-2024-47081 · https://requests.readthedocs.io/en/latest/api/#requests.Session.trust_env · https://seclists.org/fulldisclosure/2025/Jun/2

Evidence and framework references

Selected-run source: Saved result from this run · Finding ID: finding-93221aeb57ed723e1b1fea0b87b981ff

Why this priority

  • Source severity: Medium
  • Confidence derived from an installed-version match against a published advisory range; Grype reports no confidence of its own.

Evidence SHA-256

  • 9dd51b7ab648a007bdd218d4a7db4127878bcdfe07b7973f00bad465b9af7a16
    Evidence evidence-48dfcf79b87712e51edc81dfac1264cb · Check grype · Observed 2026-10-07 01:24:23 UTC
    Source rule
    GHSA-9hjg-9r4m-mvj7
    Evidence summary
    [redacted evidence summary]
    Evidence kind
    Package Inventory
    Engine run ID
    0b2ad9f4-1ecb-4533-8d34-9d895b4ca1d8
    Artifact ID
    70f5b723-a1c1-4b4c-9b5e-c00ebf0c008c
    Result pointer
    [redacted result pointer]
    Evidence location
    [redacted location]

    Scanner-provided details

    Scanner-provided description
    [redacted scanner-provided description]
    Scanner-provided installed version
    2.31.0
    Scanner-provided fixed version
    2.32.4
    Scanner-reported CVSS
    5.3 · v3.1 · scored by grype
    CVSS vector
    CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

Related framework references

  • The packaged mapping catalog has no entry for this finding's rule, so its framework position is unknown, not absent.

Vulnerable package requests 2.31.0 (CVE-2026-25645 / GHSA-gc5v-m9x4-r6x2) — Asset 1

Medium · 2 original findings

A container or software component may expose the workload to a known weakness.

Target: Asset 1

What to do next: Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.

Related checks (2)

Vulnerable package requests (GHSA-gc5v-m9x4-r6x2) — Asset 1

Severity: MediumConfidence: MediumPriority: 60Report order #15Suggested expert: Software supply-chain engineer

Grype reported a medium-severity condition on the assessed asset. Possible impact: A container or software component may expose the workload to a known weakness.

What to do next: Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.

Scanner-provided fixed version: 2.33.0

How to confirm the fix: Rerun Grype with the same scope after the change and confirm that source rule GHSA-gc5v-m9x4-r6x2 is no longer reported.

Official scanner references: https://github.com/advisories/GHSA-gc5v-m9x4-r6x2 · https://github.com/anchore/grype · https://github.com/psf/requests/commit/66d21cb07bd6255b1280291c4fafb71803cdb3b7 · https://github.com/psf/requests/releases/tag/v2.33.0 · https://github.com/psf/requests/security/advisories/GHSA-gc5v-m9x4-r6x2 · https://nvd.nist.gov/vuln/detail/CVE-2026-25645

Evidence and framework references

Selected-run source: Saved result from this run · Finding ID: finding-821475b53601212ae24027e9fb0bd772

Why this priority

  • Source severity: Medium
  • Confidence derived from an installed-version match against a published advisory range; Grype reports no confidence of its own.

Evidence SHA-256

  • 9dd51b7ab648a007bdd218d4a7db4127878bcdfe07b7973f00bad465b9af7a16
    Evidence evidence-a0f9bf9101c024fc5ae98c4f947b99aa · Check grype · Observed 2026-10-07 01:24:23 UTC
    Source rule
    GHSA-gc5v-m9x4-r6x2
    Evidence summary
    [redacted evidence summary]
    Evidence kind
    Package Inventory
    Engine run ID
    0b2ad9f4-1ecb-4533-8d34-9d895b4ca1d8
    Artifact ID
    70f5b723-a1c1-4b4c-9b5e-c00ebf0c008c
    Result pointer
    [redacted result pointer]
    Evidence location
    [redacted location]

    Scanner-provided details

    Scanner-provided description
    [redacted scanner-provided description]
    Scanner-provided installed version
    2.31.0
    Scanner-provided fixed version
    2.33.0
    Scanner-reported CVSS
    4.4 · v3.1 · scored by grype
    CVSS vector
    CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N

Related framework references

  • The packaged mapping catalog has no entry for this finding's rule, so its framework position is unknown, not absent.

requests: Requests: Security bypass due to predictable temporary file creation — Asset 1

Severity: MediumConfidence: MediumPriority: 60Report order #18Suggested expert: Software supply-chain engineer

Trivy reported a medium-severity condition on the assessed asset. Possible impact: A container or software component may expose the workload to a known weakness.

What to do next: Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.

Scanner-provided fixed version: 2.33.0

How to confirm the fix: Rerun Trivy with the same scope after the change and confirm that source rule CVE-2026-25645 is no longer reported.

Official scanner references: https://access.redhat.com/security/cve/CVE-2026-25645 · https://avd.aquasec.com/nvd/cve-2026-25645 · https://github.com/aquasecurity/trivy · https://github.com/psf/requests · https://github.com/psf/requests/commit/66d21cb07bd6255b1280291c4fafb71803cdb3b7 · https://github.com/psf/requests/releases/tag/v2.33.0 · https://github.com/psf/requests/security/advisories/GHSA-gc5v-m9x4-r6x2 · https://nvd.nist.gov/vuln/detail/CVE-2026-25645 · https://trivy.dev/ · https://www.cve.org/CVERecord?id=CVE-2026-25645

Evidence and framework references

Selected-run source: Saved result from this run · Finding ID: finding-b6575e638285a44a0c8937e97f9287fe

Why this priority

  • Source severity: MEDIUM
  • Confidence derived from an installed-version match against a published advisory range; Trivy reports no confidence of its own.

Evidence SHA-256

  • e7e05ad7497e646463da408c8db1f7b854fa593bcaffcc8d0f68d8f39c1516c8
    Evidence evidence-d9a0bc54cb36f1e6801eb5daf0f197e1 · Check trivy · Observed 2026-10-07 01:21:55 UTC
    Source rule
    CVE-2026-25645
    Evidence summary
    [redacted evidence summary]
    Evidence kind
    Package Inventory
    Engine run ID
    8ff52035-7920-4792-9015-79d5ab1e589d
    Artifact ID
    7238caea-4c23-48c4-a643-61d08c1a0d03
    Result pointer
    [redacted result pointer]
    Evidence location
    [redacted location]

    Scanner-provided details

    Scanner-provided description
    [redacted scanner-provided description]
    Scanner-provided installed version
    2.31.0
    Scanner-provided fixed version
    2.33.0
    Scanner-assigned CWE
    CWE-377
    Scanner-reported CVSS
    4.4 · v3.1 · scored by ghsa
    CVSS vector
    CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N
    Scanner-reported CVSS
    5.5 · v3.1 · scored by nvd
    CVSS vector
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
    Scanner-reported CVSS
    4.7 · v3.1 · scored by redhat
    CVSS vector
    CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N

Related framework references

  • ISO/IEC 27001 2022 / A.8.8 — Technical vulnerability handling
    Relationship: related
    Why related: Evidence that an installed component is affected by a CVE is related to vulnerability handling. For an AI system, AIDEFEND separates build or deployment admission from the deployed-software remediation lifecycle; this reference does not decide which lifecycle state applies.
  • NIST CSF 2.0 / ID.RA-01 — Vulnerability identification and recording
    Relationship: related
    Why related: Evidence that an installed component is affected by a CVE is related to vulnerability handling. For an AI system, AIDEFEND separates build or deployment admission from the deployed-software remediation lifecycle; this reference does not decide which lifecycle state applies.
  • OWASP Top 10 2021 / A06:2021 — Vulnerable and Outdated Components
    Relationship: related
    Why related: Evidence that an installed component is affected by a CVE is related to vulnerability handling. For an AI system, AIDEFEND separates build or deployment admission from the deployed-software remediation lifecycle; this reference does not decide which lifecycle state applies.
  • OWASP Top 10 2021 / A01:2021 — Broken Access Control
    Relationship: related
    Why related: OWASP publishes A01:2021 as this set of CWEs, so a scanner-assigned CWE in the set places the result in the category.

Healthcheck Instruction Missing — Asset 1

Severity: LowConfidence: HighPriority: 35Report order #19Suggested expert: Infrastructure-as-code engineer

KICS reported a low-severity condition on the assessed asset. Possible impact: Deployed infrastructure may inherit the reported insecure configuration.

What to do next: Correct the infrastructure-as-code template so redeployment does not restore the insecure setting.

How to confirm the fix: Rerun KICS with the same scope after the change and confirm that “Healthcheck Instruction Missing” is no longer reported.

Official scanner references: https://docs.docker.com/engine/reference/builder/#healthcheck · https://github.com/Checkmarx/kics · https://www.kics.io/

Evidence and framework references

Selected-run source: Saved result from this run · Finding ID: finding-21a58716ec4c5fbd166bd9a7480bb494

Why this priority

Evidence SHA-256

Related framework references

Vulnerable package flask 3.0.3 (CVE-2026-27205 / GHSA-68rp-wp8r-4726) — Asset 1

Low · 2 original findings

A container or software component may expose the workload to a known weakness.

Target: Asset 1

What to do next: Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.

Related checks (2)

Vulnerable package flask (GHSA-68rp-wp8r-4726) — Asset 1

Severity: LowConfidence: MediumPriority: 35Report order #20Suggested expert: Software supply-chain engineer

Grype reported a low-severity condition on the assessed asset. Possible impact: A container or software component may expose the workload to a known weakness.

What to do next: Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.

Scanner-provided fixed version: 3.1.3

How to confirm the fix: Rerun Grype with the same scope after the change and confirm that source rule GHSA-68rp-wp8r-4726 is no longer reported.

Official scanner references: https://github.com/advisories/GHSA-68rp-wp8r-4726 · https://github.com/anchore/grype · https://github.com/pallets/flask/commit/089cb86dd22bff589a4eafb7ab8e42dc357623b4 · https://github.com/pallets/flask/releases/tag/3.1.3 · https://github.com/pallets/flask/security/advisories/GHSA-68rp-wp8r-4726 · https://nvd.nist.gov/vuln/detail/CVE-2026-27205

Evidence and framework references

Selected-run source: Saved result from this run · Finding ID: finding-d238d1da88589599818f5ac99b0acdc7

Why this priority

  • Source severity: Low
  • Confidence derived from an installed-version match against a published advisory range; Grype reports no confidence of its own.

Evidence SHA-256

  • 9dd51b7ab648a007bdd218d4a7db4127878bcdfe07b7973f00bad465b9af7a16
    Evidence evidence-353a62d13ce2c0311d53e983a681608f · Check grype · Observed 2026-10-07 01:24:23 UTC
    Source rule
    GHSA-68rp-wp8r-4726
    Evidence summary
    [redacted evidence summary]
    Evidence kind
    Package Inventory
    Engine run ID
    0b2ad9f4-1ecb-4533-8d34-9d895b4ca1d8
    Artifact ID
    70f5b723-a1c1-4b4c-9b5e-c00ebf0c008c
    Result pointer
    [redacted result pointer]
    Evidence location
    [redacted location]

    Scanner-provided details

    Scanner-provided description
    [redacted scanner-provided description]
    Scanner-provided installed version
    3.0.3
    Scanner-provided fixed version
    3.1.3
    Scanner-reported CVSS
    2.3 · v4.0 · scored by grype
    CVSS vector
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Related framework references

  • The packaged mapping catalog has no entry for this finding's rule, so its framework position is unknown, not absent.

flask: Flask: Information disclosure via improper caching of session data — Asset 1

Severity: LowConfidence: MediumPriority: 35Report order #21Suggested expert: Software supply-chain engineer

Trivy reported a low-severity condition on the assessed asset. Possible impact: A container or software component may expose the workload to a known weakness.

What to do next: Upgrade the affected component to a fixed version; if none is available, record the blocker and track the fix.

Scanner-provided fixed version: 3.1.3

How to confirm the fix: Rerun Trivy with the same scope after the change and confirm that source rule CVE-2026-27205 is no longer reported.

Official scanner references: https://access.redhat.com/security/cve/CVE-2026-27205 · https://avd.aquasec.com/nvd/cve-2026-27205 · https://github.com/aquasecurity/trivy · https://github.com/pallets/flask · https://github.com/pallets/flask/commit/089cb86dd22bff589a4eafb7ab8e42dc357623b4 · https://github.com/pallets/flask/releases/tag/3.1.3 · https://github.com/pallets/flask/security/advisories/GHSA-68rp-wp8r-4726 · https://nvd.nist.gov/vuln/detail/CVE-2026-27205 · https://trivy.dev/ · https://ubuntu.com/security/notices/USN-8104-1 · https://www.cve.org/CVERecord?id=CVE-2026-27205

Evidence and framework references

Selected-run source: Saved result from this run · Finding ID: finding-ea18147c591cf6eeec191b9d63c2b4a8

Why this priority

  • Source severity: LOW
  • Confidence derived from an installed-version match against a published advisory range; Trivy reports no confidence of its own.

Evidence SHA-256

  • e7e05ad7497e646463da408c8db1f7b854fa593bcaffcc8d0f68d8f39c1516c8
    Evidence evidence-79de111b457a914f8e7218c84c6f2770 · Check trivy · Observed 2026-10-07 01:21:55 UTC
    Source rule
    CVE-2026-27205
    Evidence summary
    [redacted evidence summary]
    Evidence kind
    Package Inventory
    Engine run ID
    8ff52035-7920-4792-9015-79d5ab1e589d
    Artifact ID
    7238caea-4c23-48c4-a643-61d08c1a0d03
    Result pointer
    [redacted result pointer]
    Evidence location
    [redacted location]

    Scanner-provided details

    Scanner-provided description
    [redacted scanner-provided description]
    Scanner-provided installed version
    3.0.3
    Scanner-provided fixed version
    3.1.3
    Scanner-assigned CWE
    CWE-524
    Scanner-reported CVSS
    4.3 · v3.1 · scored by nvd
    CVSS vector
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
    Scanner-reported CVSS
    4.3 · v3.1 · scored by redhat
    CVSS vector
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Related framework references

  • ISO/IEC 27001 2022 / A.8.8 — Technical vulnerability handling
    Relationship: related
    Why related: Evidence that an installed component is affected by a CVE is related to vulnerability handling. For an AI system, AIDEFEND separates build or deployment admission from the deployed-software remediation lifecycle; this reference does not decide which lifecycle state applies.
  • NIST CSF 2.0 / ID.RA-01 — Vulnerability identification and recording
    Relationship: related
    Why related: Evidence that an installed component is affected by a CVE is related to vulnerability handling. For an AI system, AIDEFEND separates build or deployment admission from the deployed-software remediation lifecycle; this reference does not decide which lifecycle state applies.
  • OWASP Top 10 2021 / A06:2021 — Vulnerable and Outdated Components
    Relationship: related
    Why related: Evidence that an installed component is affected by a CVE is related to vulnerability handling. For an AI system, AIDEFEND separates build or deployment admission from the deployed-software remediation lifecycle; this reference does not decide which lifecycle state applies.

Ensure that HEALTHCHECK instructions have been added to container images — Asset 1

Severity: UnknownConfidence: HighPriority: 20Report order #22Suggested expert: Infrastructure-as-code engineer

Checkov reported this condition without a severity rating. Severity is Unknown. Possible impact: Deployed infrastructure may inherit the reported insecure configuration.

What to do next: Correct the infrastructure-as-code template so redeployment does not restore the insecure setting.

How to confirm the fix: Rerun Checkov with the same scope after the change and confirm that source rule CKV_DOCKER_2 is no longer reported.

Official scanner references: https://github.com/bridgecrewio/checkov · https://www.checkov.io/

Evidence and framework references

Selected-run source: Saved result from this run · Finding ID: finding-38e43d6117d5c77fdf7a0e58a51dcc29

Why this priority

Evidence SHA-256

Related framework references

Ensure that a user for the container has been created — Asset 1

Severity: UnknownConfidence: HighPriority: 20Report order #23Suggested expert: Infrastructure-as-code engineer

Checkov reported this condition without a severity rating. Severity is Unknown. Possible impact: Deployed infrastructure may inherit the reported insecure configuration.

What to do next: Correct the infrastructure-as-code template so redeployment does not restore the insecure setting.

How to confirm the fix: Rerun Checkov with the same scope after the change and confirm that source rule CKV_DOCKER_3 is no longer reported.

Official scanner references: https://github.com/bridgecrewio/checkov · https://www.checkov.io/

Evidence and framework references

Selected-run source: Saved result from this run · Finding ID: finding-4eaa50ebcf31d40463549976c04636a2

Why this priority

Evidence SHA-256

Related framework references

Inventory observations

Inventory observations are separate from vulnerability findings and remediation priorities.

Total: 3 · Services: 0 · Software components: 3 · Cloud resources: 0 · Inventoried assets: 1 · Representative records: 3

Inventoried asset list: Asset 1

Representative sample (maximum 3)

Complete inventory by asset

Asset 1 asset-workspace-source-ce6e9c1d-53d1-4bf2-853f-774361bdb818

  • Software component — Name [redacted software component] · version [redacted version] · package type python · purl [redacted purl]
    Source provenance
    • Observation inventory-d04a0ef58349fad2f0ae04dfd8a853c9 · engine syft · engine run 359560cc-b3a3-496b-a83a-7c0f13f41dea
      artifact 908203e6-afac-431c-8e6f-6487a2a6bf5f · SHA-256 3df6189980710d29163869954d1d6313844fa92da46b1bba79fb6d5f9a40eb0e
      pointer [redacted inventory pointer] · observed 2026-10-07 01:24:35 UTC
  • Software component — Name [redacted software component] · version [redacted version] · package type python · purl [redacted purl]
    Source provenance
    • Observation inventory-0d3fadaba7522d8f4181365baa2b6742 · engine syft · engine run 359560cc-b3a3-496b-a83a-7c0f13f41dea
      artifact 908203e6-afac-431c-8e6f-6487a2a6bf5f · SHA-256 3df6189980710d29163869954d1d6313844fa92da46b1bba79fb6d5f9a40eb0e
      pointer [redacted inventory pointer] · observed 2026-10-07 01:24:35 UTC
  • Software component — Name [redacted software component] · version [redacted version] · package type python · purl [redacted purl]
    Source provenance
    • Observation inventory-a9b7242e56cd69627324fd8ecddc54e3 · engine syft · engine run 359560cc-b3a3-496b-a83a-7c0f13f41dea
      artifact 908203e6-afac-431c-8e6f-6487a2a6bf5f · SHA-256 3df6189980710d29163869954d1d6313844fa92da46b1bba79fb6d5f9a40eb0e
      pointer [redacted inventory pointer] · observed 2026-10-07 01:24:35 UTC

Where this lands in each framework

Each reference below was reached from a finding's own rule or CWE through the packaged mapping catalog. They are navigation aids for finding the relevant control text, not a compliance result: nothing here is an audit, a certification, or a pass.

Every framework in this report and what this run shows against it
FrameworkWhat this run showsControlsFindings
NIST CSF
version 2.0
Related references observed38
ISO/IEC 27001
version 2022
Related references observed48
AIDEFEND
version 1.20260805
Unknown — the context answers are incomplete00
OWASP Top 10
version 2021
Related references observed615
OWASP Top 10 for LLM Applications
version 2025
Unknown — the context answers are incomplete00
CIS Kubernetes Benchmark
version 1.11
Unknown — coverage is incomplete00
CIS Amazon Web Services Foundations Benchmark
version 3.0.0
Unknown — coverage is incomplete00

AIDEFEND version 1.20260805, OWASP Top 10 for LLM Applications version 2025 — No reference to this AI-specific framework was inferred because at least one required AI-context answer is legacy or unanswered. This remains unknown, not not-applicable.

CIS Kubernetes Benchmark version 1.11, CIS Amazon Web Services Foundations Benchmark version 3.0.0 — No related reference was observed, but coverage is incomplete or unknown. This cannot be interpreted as a passed or implemented control.

NIST CSF version 2.0

Related references observed

NIST CSF controls with an observed reference
ControlTitleFindingsSeverity mix
ID.RA-01Vulnerability identification and recording5

Critical 1 · Medium 3 · Low 1

PR.AA-01Identity and credential lifecycle management2

High 1 · Unknown 1

PR.PS-06Secure software development practices1

High 1

ISO/IEC 27001 version 2022

Related references observed

ISO/IEC 27001 controls with an observed reference
ControlTitleFindingsSeverity mix
A.5.17Authentication information safeguards2

High 1 · Unknown 1

A.8.8Technical vulnerability handling5

Critical 1 · Medium 3 · Low 1

A.8.28Secure coding practices1

High 1

A.8.29Security testing before acceptance1

High 1

OWASP Top 10 version 2021

Related references observed

OWASP Top 10 controls with an observed reference
ControlTitleFindingsSeverity mix
A01:2021Broken Access Control1

Medium 1

A03:2021Injection6

Critical 1 · High 5

A04:2021Insecure Design2

High 1 · Medium 1

A06:2021Vulnerable and Outdated Components5

Critical 1 · Medium 3 · Low 1

A07:2021Identification and Authentication Failures3

High 2 · Informational 1

A08:2021Software and Data Integrity Failures1

High 1

Framework sources and attribution

NIST CSF version 2.0 — NIST Cybersecurity Framework (CSF) 2.0, National Institute of Standards and Technology. Use of NIST source material remains subject to the source publication's notices. Framework relationships and rationales in this report are project-authored navigation metadata. NIST has not reviewed or endorsed this report or integration. https://doi.org/10.6028/NIST.CSWP.29

ISO/IEC 27001 version 2022 — ISO/IEC 27001:2022 control coordinates are referenced nominatively. ISO/IEC standard content remains subject to ISO's terms; this report is not a copy of the standard. Framework relationships and rationales in this report are project-authored navigation metadata. ISO and IEC have not reviewed or endorsed this report or integration. https://www.iso.org/standard/27001

AIDEFEND version 1.20260805 — AIDEFEND AI Defense Framework, created by Edward Lee, https://aidefend.net, licensed under CC BY 4.0. Creative Commons Attribution 4.0 International: https://creativecommons.org/licenses/by/4.0/ ai-security-scanner uses a modified, project-authored six-record metadata selection from AIDEFEND 1.20260805 at pinned commit e10c1678ee49f03f8fb0c97d446ba3fbc3543655. This independent integration is not affiliated with, approved, certified, sponsored, or endorsed by AIDEFEND or its owner. https://github.com/edward-playground/aidefense-framework/blob/e10c1678ee49f03f8fb0c97d446ba3fbc3543655/data/data.json

OWASP Top 10 version 2021 — OWASP Top 10:2021, Copyright (c) 2003-2025 The OWASP Foundation, Inc., licensed under CC BY-SA 4.0. Creative Commons Attribution-ShareAlike 4.0 International: https://creativecommons.org/licenses/by-sa/4.0/ Category membership is read from the CWE sets OWASP publishes for each 2021 category; the rationales beside them are project-authored navigation metadata. The OWASP Foundation has not reviewed or endorsed this report or integration. https://owasp.org/Top10/

OWASP Top 10 for LLM Applications version 2025 — OWASP Top 10 for LLM Applications 2025, OWASP GenAI Security Project, Copyright (c) The OWASP Foundation, Inc., licensed under CC BY-SA 4.0. Creative Commons Attribution-ShareAlike 4.0 International: https://creativecommons.org/licenses/by-sa/4.0/ This report references three of the ten 2025 categories, the only ones the packaged engines produce evidence for; the rationales are project-authored navigation metadata. The OWASP Foundation and the OWASP GenAI Security Project have not reviewed or endorsed this report or integration. https://genai.owasp.org/llm-top-10/

CIS Kubernetes Benchmark version 1.11 — CIS Kubernetes Benchmark v1.11 recommendation numbers and titles are referenced nominatively; they are the coordinates kube-bench itself reports against. CIS Benchmark content remains subject to the Center for Internet Security's terms of use; this report is not a copy of the benchmark. Recommendation titles are reproduced as the pinned kube-bench image reports them. The Center for Internet Security has not reviewed or endorsed this report or integration. https://www.cisecurity.org/benchmark/kubernetes

CIS Amazon Web Services Foundations Benchmark version 3.0.0 — CIS Amazon Web Services Foundations Benchmark v3.0.0 recommendation numbers and titles are referenced nominatively. CIS Benchmark content remains subject to the Center for Internet Security's terms of use; this report is not a copy of the benchmark. The recommendation-to-check relationship is the one Prowler publishes in its own CIS 3.0 compliance file. The Center for Internet Security has not reviewed or endorsed this report or integration. https://www.cisecurity.org/benchmark/amazon_web_services

Technical details

Exact requested identities

Target IDs

Check IDs

Selected-run task details

Redacted diagnostic log

Every task in this run recorded the same state.

Availability: Unavailable
Run-bound diagnostic log: unavailable. Redacted diagnostic export: separate.

Scanner messages are not included in this readable HTML report.

Task 0b2ad9f4-1ecb-4533-8d34-9d895b4ca1d8

State: Completed · Progress: 100%

Started: 2026-10-07 01:11:59 UTC · Finished: 2026-10-07 01:24:24 UTC · Targets: asset-workspace-source-ce6e9c1d-53d1-4bf2-853f-774361bdb818

Exit code: 0 · Error code: none recorded · Cleanup: removed=true

Execution identity: engine grype; adapter 0.2.6; engine version 0.117.0; last updated 2026-08-24; image repository ghcr.io/teddashh/ai-security-scanner-engine-grype; image sha256:56b0d675e3b8d539890e853699c114493a72a54cca0bbe254eceee7ec2b4c517; command SHA-256 4f696152031992a5af1d4a3dac05cc5699bd3c2da3aa188ff5571a3053cb9067; runtime managed_local; runtime version 5.8.2; runtime security {"apparmorEnabled":false,"capabilities":"CAP_CHOWN,CAP_DAC_OVERRIDE,CAP_FOWNER,CAP_FSETID,CAP_KILL,CAP_NET_BIND_SERVICE,CAP_SETFCAP,CAP_SETGID,CAP_SETPCAP,CAP_SETUID,CAP_SYS_CHROOT","rootless":true,"seccompEnabled":true,"seccompProfilePath":"/usr/share/containers/seccomp.json","selinuxEnabled":true}; distribution Pull Pinned Image; rules b5fa92bbcbef655497e3be840a2f718380e2cdd3

Evidence SHA-256

Task 359560cc-b3a3-496b-a83a-7c0f13f41dea

State: Completed · Progress: 100%

Started: 2026-10-07 01:11:59 UTC · Finished: 2026-10-07 01:24:36 UTC · Targets: asset-workspace-source-ce6e9c1d-53d1-4bf2-853f-774361bdb818

Exit code: 0 · Error code: none recorded · Cleanup: removed=true

Execution identity: engine syft; adapter 0.2.6; engine version 1.51.0; last updated 2026-08-24; image repository ghcr.io/teddashh/ai-security-scanner-engine-syft; image sha256:805c9fe522113319f994f99cd68fcb5c18e322dd933e7d89f82cd91f5a5c8501; command SHA-256 a8c38b73e0b1e3e95fc043d1554adba51ef64d4eec964a87fb179865ce4d14b5; runtime managed_local; runtime version 5.8.2; runtime security {"apparmorEnabled":false,"capabilities":"CAP_CHOWN,CAP_DAC_OVERRIDE,CAP_FOWNER,CAP_FSETID,CAP_KILL,CAP_NET_BIND_SERVICE,CAP_SETFCAP,CAP_SETGID,CAP_SETPCAP,CAP_SETUID,CAP_SYS_CHROOT","rootless":true,"seccompEnabled":true,"seccompProfilePath":"/usr/share/containers/seccomp.json","selinuxEnabled":true}; distribution Pull Pinned Image; rules 2293641e3bd628a01bb37639318d62c0ebe89b39

Evidence SHA-256

Task 6cf3025f-2143-47c1-a0e2-407dd85d0ac1

State: Completed · Progress: 100%

Started: 2026-10-07 01:11:59 UTC · Finished: 2026-10-07 01:23:13 UTC · Targets: asset-workspace-source-ce6e9c1d-53d1-4bf2-853f-774361bdb818

Exit code: 0 · Error code: none recorded · Cleanup: removed=true

Execution identity: engine checkov; adapter 0.2.6; engine version 3.3.13; last updated 2026-08-24; image repository ghcr.io/teddashh/ai-security-scanner-engine-checkov; image sha256:0ecc187b17faa9c538c9b1ecc08a4195283290222694d0f87d50016f2bb79b35; command SHA-256 e4c81c7a215769616f0e68122333d6ceee3db3aebfc085861b8488e013ca2bf1; runtime managed_local; runtime version 5.8.2; runtime security {"apparmorEnabled":false,"capabilities":"CAP_CHOWN,CAP_DAC_OVERRIDE,CAP_FOWNER,CAP_FSETID,CAP_KILL,CAP_NET_BIND_SERVICE,CAP_SETFCAP,CAP_SETGID,CAP_SETPCAP,CAP_SETUID,CAP_SYS_CHROOT","rootless":true,"seccompEnabled":true,"seccompProfilePath":"/usr/share/containers/seccomp.json","selinuxEnabled":true}; distribution Pull Pinned Image; rules 0604e97b0f77c89a8c6c1fe2219c3d251cbb9789

Evidence SHA-256

Task 8ff52035-7920-4792-9015-79d5ab1e589d

State: Completed · Progress: 100%

Started: 2026-10-07 01:11:59 UTC · Finished: 2026-10-07 01:21:55 UTC · Targets: asset-workspace-source-ce6e9c1d-53d1-4bf2-853f-774361bdb818

Exit code: 0 · Error code: none recorded · Cleanup: removed=true

Execution identity: engine trivy; adapter 0.2.6; engine version 0.74.0; last updated 2026-08-24; image repository ghcr.io/teddashh/ai-security-scanner-engine-trivy; image sha256:9bfcef9a6a9d9a69eefcece06b0670eaed72541656b65155469b41acb3855dc2; command SHA-256 fd202ea65d8acd07cdca370a1569531b92eb306148db6a19df23270c73618540; runtime managed_local; runtime version 5.8.2; runtime security {"apparmorEnabled":false,"capabilities":"CAP_CHOWN,CAP_DAC_OVERRIDE,CAP_FOWNER,CAP_FSETID,CAP_KILL,CAP_NET_BIND_SERVICE,CAP_SETFCAP,CAP_SETGID,CAP_SETPCAP,CAP_SETUID,CAP_SYS_CHROOT","rootless":true,"seccompEnabled":true,"seccompProfilePath":"/usr/share/containers/seccomp.json","selinuxEnabled":true}; distribution Pull Pinned Image; rules e1fd17a0ea4a8cf24bc4b4dd7e2cfbf4bb31b994

Evidence SHA-256

Task 92ed7ef7-7499-424e-b760-7f992357b07a

State: Completed · Progress: 100%

Started: 2026-10-07 01:11:59 UTC · Finished: 2026-10-07 01:21:28 UTC · Targets: asset-workspace-source-ce6e9c1d-53d1-4bf2-853f-774361bdb818

Exit code: 0 · Error code: none recorded · Cleanup: removed=true

Execution identity: engine semgrep; adapter 0.2.6; engine version 1.174.0 (source@a0c13f304151e531c7e7c00838076211a07a790c); last updated 2026-08-24; image repository ghcr.io/teddashh/ai-security-scanner-engine-semgrep; image sha256:3f1a10c7bce32eae912479c5744dbb653bdfa9a4cbd3d53afd2e0a435b10fb59; command SHA-256 e8957f5e89fd6d47b138eb49c8548af09d5a7da3f26dd09ab6b8fdf6f92bd188; runtime managed_local; runtime version 5.8.2; runtime security {"apparmorEnabled":false,"capabilities":"CAP_CHOWN,CAP_DAC_OVERRIDE,CAP_FOWNER,CAP_FSETID,CAP_KILL,CAP_NET_BIND_SERVICE,CAP_SETFCAP,CAP_SETGID,CAP_SETPCAP,CAP_SETUID,CAP_SYS_CHROOT","rootless":true,"seccompEnabled":true,"seccompProfilePath":"/usr/share/containers/seccomp.json","selinuxEnabled":true}; distribution Pull Pinned Image; rules 0f5a85ceab1b82b193d0eaa418784c932d237d68

Evidence SHA-256

Task 9cdabc03-7812-4c7e-ad4c-b3421fe0f51c

State: Completed · Progress: 100%

Started: 2026-10-07 01:11:59 UTC · Finished: 2026-10-07 01:22:09 UTC · Targets: asset-workspace-source-ce6e9c1d-53d1-4bf2-853f-774361bdb818

Exit code: 0 · Error code: none recorded · Cleanup: removed=true

Execution identity: engine trufflehog; adapter 0.2.6; engine version 3.97.0 (source@3ab759fef4bb5935d4fe9ac68b503d05346b8364); last updated 2026-08-24; image repository ghcr.io/teddashh/ai-security-scanner-engine-trufflehog; image sha256:dd0e0879bc4d3ac79194d6c734d2a2636cc83fdacb01f611b6b3284fe86dd55a; command SHA-256 87559bf62666b22b4d5687211deeb33c256ee3b901a232718fe85f84eacfb67a; runtime managed_local; runtime version 5.8.2; runtime security {"apparmorEnabled":false,"capabilities":"CAP_CHOWN,CAP_DAC_OVERRIDE,CAP_FOWNER,CAP_FSETID,CAP_KILL,CAP_NET_BIND_SERVICE,CAP_SETFCAP,CAP_SETGID,CAP_SETPCAP,CAP_SETUID,CAP_SYS_CHROOT","rootless":true,"seccompEnabled":true,"seccompProfilePath":"/usr/share/containers/seccomp.json","selinuxEnabled":true}; distribution Pull Pinned Image; rules 3ab759fef4bb5935d4fe9ac68b503d05346b8364

Evidence SHA-256

Task b28b74f2-e4dc-459a-8d56-ec345acdd068

State: Completed · Progress: 100%

Started: 2026-10-07 01:11:59 UTC · Finished: 2026-10-07 01:13:30 UTC · Targets: asset-workspace-source-ce6e9c1d-53d1-4bf2-853f-774361bdb818

Exit code: 0 · Error code: none recorded · Cleanup: removed=true

Execution identity: engine gitleaks; adapter 0.2.6; engine version 8.30.1; last updated 2026-08-24; image repository ghcr.io/teddashh/ai-security-scanner-engine-gitleaks; image sha256:95313654f9c37115a906629a82113ba6e1c729950be70909da8362e9482b477e; command SHA-256 76d7d6583c581bada2a5cf02eeda810a3856756e152bb5bbdb7f73dc1bd3c0f0; runtime managed_local; runtime version 5.8.2; runtime security {"apparmorEnabled":false,"capabilities":"CAP_CHOWN,CAP_DAC_OVERRIDE,CAP_FOWNER,CAP_FSETID,CAP_KILL,CAP_NET_BIND_SERVICE,CAP_SETFCAP,CAP_SETGID,CAP_SETPCAP,CAP_SETUID,CAP_SYS_CHROOT","rootless":true,"seccompEnabled":true,"seccompProfilePath":"/usr/share/containers/seccomp.json","selinuxEnabled":true}; distribution Pull Pinned Image; rules sha256:e163e53b9e7e8a8511e77271e2b323ed057759542a6d988258afe3a1fa329caf

Evidence SHA-256

Task b6dc0a53-aa7b-47eb-9d4e-33d03c49f6e4

State: Completed · Progress: 100%

Started: 2026-10-07 01:11:59 UTC · Finished: 2026-10-07 01:22:24 UTC · Targets: asset-workspace-source-ce6e9c1d-53d1-4bf2-853f-774361bdb818

Exit code: 0 · Error code: none recorded · Cleanup: removed=true

Execution identity: engine kics; adapter 0.2.6; engine version 2.1.20; last updated 2026-08-24; image repository checkmarx/kics; image sha256:3e5a268eb8adda2e5a483c9359ddfc4cd520ab856a7076dc0b1d8784a37e2602; command SHA-256 d0194e28734693b5ecdd5dfb8700979035a4ba6a55847c93e6be0e7a40aa1d01; runtime managed_local; runtime version 5.8.2; runtime security {"apparmorEnabled":false,"capabilities":"CAP_CHOWN,CAP_DAC_OVERRIDE,CAP_FOWNER,CAP_FSETID,CAP_KILL,CAP_NET_BIND_SERVICE,CAP_SETFCAP,CAP_SETGID,CAP_SETPCAP,CAP_SETUID,CAP_SYS_CHROOT","rootless":true,"seccompEnabled":true,"seccompProfilePath":"/usr/share/containers/seccomp.json","selinuxEnabled":true}; distribution Pull Pinned Image; rules e1f23cad9640f55b963f22a116b04906b8c16ac6

Evidence SHA-256

Report data-quality notes

Reversible finding groups

Groups are presentation metadata only. Every canonical finding, fingerprint, evidence record, and raw artifact remains independent; removing a group appends history and does not delete its members.

No active presentation groups are recorded.

Immutable grouping history

Every grouping event recorded for this case, oldest first
TimeActionGroup IDTitleFinding IDsReasonActor
No grouping events are recorded.