Transom

AIVSS (AI Vulnerability Scoring System)

Also called: AIVSS

An effort to standardize severity scoring for AI-specific weaknesses — agentic behavior, prompt injection, model risks — where traditional CVSS fits poorly.

CVSS was built for conventional software vulnerabilities and struggles with issues like "this agent can be prompt-injected into misusing its tools," where exploitability is probabilistic and impact depends on deployment. AIVSS is an official OWASP project, unveiled at OWASP Global AppSec in 2025. It starts from a CVSS base score, adds an agentic-capabilities assessment weighing autonomy, non-determinism, and tool use, and factors in environmental context. It is young and still evolving.

Why it matters

Consistent scoring is what lets teams prioritize across many findings and vendors compare notes. A dedicated framework for AI risk is likely necessary; which one wins, and how stable its scores are, is not yet settled. Treat current AIVSS scores as informative, not authoritative.

Exposure map

Live counts of instances showing this pattern will appear here once the exposure map is collecting data.

Related terms

Sources

Added 2026-09-02. Last reviewed 2026-09-08. Definitions in this space are evolving; entries are dated so revisions stay legible.