# larlarua/AutoCVE

Agent-driven automated CVE discovery platform for source code auditing, vulnerability verification, and report generation.

Repository: https://github.com/larlarua/AutoCVE
Canonical: https://ross.abutalabs.com/products/autocve
Language: Python
License: AGPL-3.0
License Family: copyleft
Topics: agent, ai-security, code-audit, cve, fastapi, llm-agent, multi-agent, penetration-testing, react, security-audit, security-tools, source-code-analysis, vulnerability-detection, vulnerability-research
Last push: 2026-08-20T07:33:40+00:00

## Health v2 (maintenance only)
Score: 77/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 98, release rhythm 92, longevity 5
- inputs: {"age_days": 79, "days_push": 13, "days_rel": 52, "gap_med": 7, "n_releases_24m": 6}
- flags: young
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1280, forks 101 (observed 2026-08-28T04:04:13.573598+00:00)

## What it is
AutoCVE is a self-hosted multi-agent platform that automates CVE discovery: it filters target projects, imports repositories, audits source code with coordinated LLM agents, verifies vulnerabilities, and generates CVE submission reports. It is built with FastAPI and React, deployed via Docker Compose, and offers three audit modes balancing scan speed and analysis depth.

## Use cases
- automatically discover CVEs in open-source projects
- audit source code for vulnerabilities with AI agents
- filter false positives from scanner results
- verify suspected vulnerabilities dynamically
- generate CVE submission reports automatically
- research 0-day vulnerabilities in source code
- manage discovered vulnerabilities in one place

## When to choose
- you want an end-to-end automated pipeline from repo selection to CVE report
- you need multi-agent source code analysis with triage and verification
- you want a self-hosted vulnerability research workbench with a web UI

## When to avoid
- you need a lightweight CLI-only scanner without LLM dependencies
- you require a commercially licensed tool (AGPL-3.0 applies)
- you need guaranteed vulnerability detection rather than AI-assisted research

## Facets
- artifact type: application
- maturity: active
- function: agent-framework, security, vulnerability-scanning, penetration-testing, llm-inference, web-framework
- domain: security, penetration-testing, artificial-intelligence, developer-tools
- platform: self-hosted, python
- tags: cve-discovery, multi-agent, source-code-audit, vulnerability-research, fastapi, react, report-generation, ai-agents, docker, web-server

## Member repositories
- larlarua/AutoCVE (main) score 77

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:13.573598+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T05:02:37.777489+00:00, confidence not recorded.
  - readme: https://github.com/larlarua/AutoCVE (fetched 2026-08-28T04:04:13.573598+00:00, sha c770f62255c6)
- Data as of 2026-08-30T08:39:29.467469+00:00.
