Skip to main content

cvss-estimator

Two things in one small, dependency-free package:

  1. A correct CVSS v3.1 base-score calculator — build, parse, and score vectors per the official specification arithmetic.
  2. An evidence-driven estimator — turn source-to-sink evidence flags (is the attacker path complete? is there a sanitizer? a public entrypoint?) plus a CWE/summary into a plausible, explainable CVSS vector and score. Useful for generating a stable machine baseline before a human refines it.

Install

pip install cvss-estimator

Scoring an existing vector

from cvss_estimator import cvss_base_score, parse_vector, severity

metrics = parse_vector("CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H")
score = cvss_base_score(metrics)   # 9.8
print(severity(score))             # "Critical"
cvss-estimator score "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"

Estimating a vector from evidence

from cvss_estimator import estimate

result = estimate(
    cwe="CWE-502",  # unsafe deserialization -> RCE category
    evidence={
        "attacker_path_complete": True,   # full source-to-sink -> AC:L, AV:N
        "entrypoint_found": True,
        "sanitizer_or_allowlist_present": False,
    },
)
print(result["vector"])    # CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
print(result["score"])     # 9.8
print(result["severity"])  # Critical
cvss-estimator estimate --cwe CWE-502 --complete-path --entrypoint http_route

Evidence flags

Flag Effect
attacker_path_complete AC:L (and AV:N for RCE)
entrypoint / entrypoint_found network attack vector for RCE
auth_guard_present PR:L
consumer_opt_in_required UI:R
sanitizer_or_allowlist_present downgrades C/I/A, raises AC:H
safe_containment_present downgrades C/I/A, raises AC:H

Categories are inferred from CWE/summary via impact_profile(): remote_code_execution, sql_injection, ssrf, xxe, path_traversal, secret_exposure, denial_of_service, security_weakness.

Notes

  • No runtime dependencies.
  • The estimator is a heuristic baseline, not an authoritative score — always have a human confirm the vector before publishing a CVE.

License

MIT

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distributions

No source distribution files available for this release.See tutorial on generating distribution archives.

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

cvss_estimator-0.1.0-py3-none-any.whl (8.7 kB view details)

Uploaded Python 3

File details

Details for the file cvss_estimator-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: cvss_estimator-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 8.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.10.11

File hashes

Hashes for cvss_estimator-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 5adc89e90c38dd731a6b0bf69425d780bc26b2dc60aaa8f5a0ce29305642e4e2
MD5 a99a026abe14fe77951e0130dd43678d
BLAKE2b-256 ae252091c5ab0ea958ca7b98d47a98142530cde096d279d36bcc1f5564e5f073

See more details on using hashes here.

Release history Release notifications | RSS feed

This release

0.1.0 This release

1 file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page