Ross ROSS = Recommend OSS · open-source software intelligence for agents

larlarua/AutoCVE

Agent-driven automated CVE discovery platform for source code auditing, vulnerability verification, and report generation. observed · 2026-08-28

github.com/larlarua/AutoCVE · Python · AGPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

77/100

  • Activity 98
  • Release rhythm 92
  • Longevity 5

Flags: young

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 7
  • age_days: 79
  • days_rel: 52
  • days_push: 13
  • n_releases_24m: 6

Full methodology

Adoption not part of the score

1280 stars · 101 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

AutoCVE is a self-hosted multi-agent platform that automates CVE discovery: it filters target projects, imports repositories, audits source code with coordinated LLM agents, verifies vulnerabilities, and generates CVE submission reports. It is built with FastAPI and React, deployed via Docker Compose, and offers three audit modes balancing scan speed and analysis depth.

Use cases

  • automatically discover CVEs in open-source projects
  • audit source code for vulnerabilities with AI agents
  • filter false positives from scanner results
  • verify suspected vulnerabilities dynamically
  • generate CVE submission reports automatically
  • research 0-day vulnerabilities in source code
  • manage discovered vulnerabilities in one place

When to choose

  • you want an end-to-end automated pipeline from repo selection to CVE report
  • you need multi-agent source code analysis with triage and verification
  • you want a self-hosted vulnerability research workbench with a web UI

When to avoid

  • you need a lightweight CLI-only scanner without LLM dependencies
  • you require a commercially licensed tool (AGPL-3.0 applies)
  • you need guaranteed vulnerability detection rather than AI-assisted research

Facets

application · maturity active

agent-framework security vulnerability-scanning penetration-testing llm-inference web-framework security penetration-testing artificial-intelligence developer-tools self-hosted python cve-discovery multi-agent source-code-audit vulnerability-research fastapi react report-generation ai-agents docker web-server

1 source

Member repositories

RepositoryRoleHealth v2
larlarua/AutoCVEmain77

For agents

markdown · JSON · MCP: product_card(name="larlarua/AutoCVE")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem