Create a vulnerability
Creates a third-party finding. VM stores source as api (app id) and the finding SK as api#{id}. The client cannot send source.
Create vulnerabilityId is a CVE or VUL- plus four digits. The response is the same object as GET, with vulnerabilityId set to the URL-encoded finding SK (api%23{id}).
firstSeen is Unix epoch milliseconds. affectedResources is an array of { name, type, tags } (max 3 tags per asset).
Idempotency-Key is required. The same key and payload replays the stored 2xx for 24 hours.
Requires scope vulnerability:write.
curl -X POST "https://api.scrut.io/v1/vulnerabilities" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: 7c9e6679-7425-40de-944b-e07fc1f90ae7" \
-H "Authorization: Bearer YOUR_API_TOKEN (JWT)" \
-d '{
"vulnerabilityId": "VUL-5672",
"title": "Public S3 bucket",
"description": "Bucket is world-readable.",
"remediation": "Block public ACLs.",
"stepsToReproduce": "Open the bucket URL.",
"severity": "high",
"status": "open",
"fixAvailable": "no",
"firstSeen": 1704067200000,
"affectedResources": [
{
"name": "s3://bucket",
"type": "s3",
"tags": [
"public",
"prod"
]
}
],
"assigneeEmail": "jordan@example.com"
}'
import requests
import json
url = "https://api.scrut.io/v1/vulnerabilities"
headers = {
"Content-Type": "application/json",
"Idempotency-Key": "7c9e6679-7425-40de-944b-e07fc1f90ae7",
"Authorization": "Bearer YOUR_API_TOKEN (JWT)"
}
data = {
"vulnerabilityId": "VUL-5672",
"title": "Public S3 bucket",
"description": "Bucket is world-readable.",
"remediation": "Block public ACLs.",
"stepsToReproduce": "Open the bucket URL.",
"severity": "high",
"status": "open",
"fixAvailable": "no",
"firstSeen": 1704067200000,
"affectedResources": [
{
"name": "s3://bucket",
"type": "s3",
"tags": [
"public",
"prod"
]
}
],
"assigneeEmail": "jordan@example.com"
}
response = requests.post(url, headers=headers, json=data)
print(response.json())
const response = await fetch("https://api.scrut.io/v1/vulnerabilities", {
method: "POST",
headers: {
"Content-Type": "application/json",
"Idempotency-Key": "7c9e6679-7425-40de-944b-e07fc1f90ae7",
"Authorization": "Bearer YOUR_API_TOKEN (JWT)"
},
body: JSON.stringify({
"vulnerabilityId": "VUL-5672",
"title": "Public S3 bucket",
"description": "Bucket is world-readable.",
"remediation": "Block public ACLs.",
"stepsToReproduce": "Open the bucket URL.",
"severity": "high",
"status": "open",
"fixAvailable": "no",
"firstSeen": 1704067200000,
"affectedResources": [
{
"name": "s3://bucket",
"type": "s3",
"tags": [
"public",
"prod"
]
}
],
"assigneeEmail": "jordan@example.com"
})
});
const data = await response.json();
console.log(data);
package main
import (
"fmt"
"net/http"
"bytes"
"encoding/json"
)
func main() {
data := []byte(`{
"vulnerabilityId": "VUL-5672",
"title": "Public S3 bucket",
"description": "Bucket is world-readable.",
"remediation": "Block public ACLs.",
"stepsToReproduce": "Open the bucket URL.",
"severity": "high",
"status": "open",
"fixAvailable": "no",
"firstSeen": 1704067200000,
"affectedResources": [
{
"name": "s3://bucket",
"type": "s3",
"tags": [
"public",
"prod"
]
}
],
"assigneeEmail": "jordan@example.com"
}`)
req, err := http.NewRequest("POST", "https://api.scrut.io/v1/vulnerabilities", bytes.NewBuffer(data))
if err != nil {
panic(err)
}
req.Header.Set("Content-Type", "application/json")
req.Header.Set("Idempotency-Key", "7c9e6679-7425-40de-944b-e07fc1f90ae7")
req.Header.Set("Authorization", "Bearer YOUR_API_TOKEN (JWT)")
client := &http.Client{}
resp, err := client.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
fmt.Println("Response Status:", resp.Status)
}
require 'net/http'
require 'json'
uri = URI('https://api.scrut.io/v1/vulnerabilities')
http = Net::HTTP.new(uri.host, uri.port)
http.use_ssl = true
request = Net::HTTP::Post.new(uri)
request['Content-Type'] = 'application/json'
request['Idempotency-Key'] = '7c9e6679-7425-40de-944b-e07fc1f90ae7'
request['Authorization'] = 'Bearer YOUR_API_TOKEN (JWT)'
request.body = '{
"vulnerabilityId": "VUL-5672",
"title": "Public S3 bucket",
"description": "Bucket is world-readable.",
"remediation": "Block public ACLs.",
"stepsToReproduce": "Open the bucket URL.",
"severity": "high",
"status": "open",
"fixAvailable": "no",
"firstSeen": 1704067200000,
"affectedResources": [
{
"name": "s3://bucket",
"type": "s3",
"tags": [
"public",
"prod"
]
}
],
"assigneeEmail": "jordan@example.com"
}'
response = http.request(request)
puts response.body
{
"data": {
"vulnerabilityId": "api%23VUL-5672",
"title": "Public S3 bucket",
"description": "Bucket is world-readable.",
"status": "open",
"severity": "high",
"source": "api",
"assignees": [
{
"name": "Jordan Kim",
"email": "jordan@example.com",
"isPrimary": true
}
],
"firstSeen": 1704067200000,
"cveId": "",
"affectedResources": [
{
"name": "s3://bucket",
"type": "s3",
"tags": [
"public",
"prod"
]
}
],
"remediation": "Block public ACLs.",
"stepsToReproduce": "Open the bucket URL.",
"customFields": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "validation_failed",
"message": "Request validation failed.",
"details": [
{
"field": "status",
"message": "status contains unknown value(s): unknown"
}
]
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "unauthorized",
"message": "Missing, malformed, or invalid Bearer token.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "token_revoked",
"message": "The API credential was revoked.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "token_stale",
"message": "The access token is stale; obtain a new token.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "forbidden",
"message": "Insufficient scope.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "not_found",
"message": "The requested resource was not found.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "idempotency_key_reused",
"message": "Idempotency key was reused with a different request body.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "idempotency_request_in_progress",
"message": "A request with this idempotency key is already being processed.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "rate_limit_exceeded",
"message": "Rate limit exceeded.",
"details": [
{
"retryAfterSec": 12
}
]
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "internal_error",
"message": "An unexpected error occurred.",
"details": []
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
{
"error": {
"code": "upstream_unavailable",
"message": "Upstream service is unavailable.",
"details": [
{
"dependency": "frameworks",
"issue": "Failed to process frameworks."
}
]
},
"meta": {
"requestId": "550e8400-e29b-41d4-a716-446655440000"
}
}
/v1/vulnerabilities
Target server for requests. Edit to use your own host.
Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.
POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.The media type of the request body
Client-generated key identifying one logical write. 1–128 characters; letters, numbers, and . _ ~ - only. Reuse the same key and body to retry safely. Reusing a key with a different body returns 409 idempotency_key_reused. Successful 2xx responses are replayed for 24 hours.
CVE id or VUL- followed by four digits. The stored SK is import#{vulnerabilityId}.
Unix epoch milliseconds.
Request Preview
Response
Response will appear here after sending the request
Authentication
Bearer token (JWT). Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.
Headers
Client-generated key identifying one logical write. 1–128 characters; letters, numbers, and . _ ~ - only. Reuse the same key and body to retry safely. Reusing a key with a different body returns 409 idempotency_key_reused. Successful 2xx responses are replayed for 24 hours.
7c9e6679-7425-40de-944b-e07fc1f90ae7Body
CVE id or VUL- followed by four digits. The stored SK is import#\\{vulnerabilityId\\}.
VUL-5672Public S3 bucketBucket is world-readable.Block public ACLs.Open the bucket URL.criticalhighmediumlowopenclosedacknowledgedyesnojordan@example.com