Skip to main content

Vulnerability Explorer (vex)

A git-native, interactive terminal reference and structured knowledge base for software vulnerabilities.

What is Vulnerability Explorer?

Imagine man pages built specifically for application security. Vulnerability Explorer is a curated, structured knowledge base of software vulnerabilities combined with a versatile command-line tool (vex).

Each entry in the catalog is an atomic Markdown file enriched with structured YAML frontmatter. Entries document concrete vulnerability mechanisms across languages, frameworks, and architectures, detailing:

  • White-box identification (Vulnerable vs. Safe code snippets, Source/Sink taint patterns)
  • Gray/Black-box behavior (Observable indicators, protocol tells, timing characteristics)
  • Remediation & Fixes (Primary patches, alternative approaches, common mistakes)

[!NOTE] This is a knowledge base, not a scanner. It is designed for security engineers reviewing code, developers learning secure coding, AI agents generating structured security documentation, and CLI lovers looking for fast terminal references.

Key Features

  • Interactive Terminal CLI (vex): Built-in arrow-key interactive menu for seamless browsing.
  • Built-in Pager Reading: Read rich formatted documentation in the terminal with built-in scrolling (less-style).
  • Multi-dimensional Filtering: Filter entries by category, programming language, or analysis mode (white-box / black-box).
  • Full-Text Search: Instantly query across titles, tags, code snippets, and methodologies.
  • AI-Native Workflow: Pre-built LLM prompts in .github/prompts/ to easily author new entries with strict quality standards.
  • Structural Linter (vex-lint): Strict schema, taxonomy, and reference validation tool for contributors and CI/CD pipelines.

Who is this for?

Audience How They Use Vulnerability Explorer
Security Engineers Fast reference during penetration tests, code audits, and report writing.
Developers Learn vulnerability root causes and compare side-by-side vulnerable vs. safe code.
AI Agents & LLMs Consume structured YAML/Markdown entries or generate new ones using .github/prompts/.
Educators & Students Study standardized vulnerability taxonomy and recognition signals.

Quick Start

1. Installation

From PyPI

# Using pip
pip install vulnerability-explorer

# Or using uv
uv pip install vulnerability-explorer

From Source (For Contributors)

Clone the repository and install in editable mode:

git clone https://github.com/othonhugo/vulnerability-explorer.git
cd vulnerability-explorer

# Using uv (recommended)
uv pip install -e .

# Or standard pip
pip install -e .

2. Launch Interactive Mode

Simply type vex to launch the interactive arrow-key navigation menu:

vex

CLI Usage Overview

Task Command
Interactive Menu vex or vex interactive
View Catalog Hierarchy vex tree
Filter by Category vex list --category injection
Filter by Language & Mode vex list --language python --mode white-box
Read Specific Entry vex read injection.sql-injection
Search Catalog vex search "prepared statement"
Plain Text Output (No Colors) vex list --no-rich

For full CLI options, flags, and advanced usage, see the CLI Commands Reference.

Catalog Structure At A Glance

The catalog is organized logically under data/:

data/
├── catalog/                   # Vulnerability classes & manifestations
│   ├── access-control/
│   ├── injection/
│   │   ├── sql-injection/
│   │   │   ├── README.md      # Concept entry (e.g. injection.sql-injection)
│   │   │   └── ...            # Manifestation entries
│   │   └── ...
│   └── ...
└── signatures/                # Runtime behavioral signatures
    └── ...

Developer & Contributor Tools

If you are authoring entries or developing the vex CLI:

# Run catalog integrity linter
vex-lint --root .
# or via Makefile
make lint

# Run Python code linters (Ruff & Mypy)
make lint-py

# Format Markdown/YAML (Prettier) and Python (Ruff)
make format
make format-py

# Run all CI checks
make check

Non-Goals

This repository does not contain weaponized exploits or automated scanning engines. Entries document recognition signals, root causes, and exploitation methodology necessary to understand, confirm, and fix vulnerabilities responsibly. See docs/contributing/guides/authoring.md for our ethical boundary guidelines.

Metadata

Release files for vulnerability-explorer 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for vulnerability-explorer 1.0.0
File Size Uploaded
vulnerability_explorer-1.0.0.tar.gz 20.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for vulnerability-explorer 1.0.0
File Interpreter ABI Platform
vulnerability_explorer-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 46.9 kB

Release files / vulnerability_explorer-1.0.0.tar.gz

Download URL vulnerability_explorer-1.0.0.tar.gz
Size 20.2 kB
Tags Source
SHA-256 checksum
How to use checksums
be427fd9124dcb6bf0add9e3a2a6c81947ae57e9d3a4722a0c3e9e5cb9fe595d
BLAKE2b-256 checksum
How to use checksums
e4ba5b58464ff94b2e72be9066d6928714334fcc8e2abf1528321d22153526cf
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 26, 2026.

Transparency log

Release files / vulnerability_explorer-1.0.0-py3-none-any.whl

Download URL vulnerability_explorer-1.0.0-py3-none-any.whl
Size 26.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
80a729e211f5165806cff05e48bdce892d6ddadad1b0599c48916846d7d81e8e
BLAKE2b-256 checksum
How to use checksums
66ad3463dc821b7b6864f39f26c562ee15e23affba892913940a0e0fa1970f93
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 26, 2026.

Transparency log

Release history Release notifications | RSS feed

1.0.3

2 release files

This release

1.0.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page