VulnerabilitiesCreate a vulnerability

Create a vulnerability

Creates a third-party finding. VM stores source as api (app id) and the finding SK as api#{id}. The client cannot send source. Create vulnerabilityId is a CVE or VUL- plus four digits. The response is the same object as GET, with vulnerabilityId set to the URL-encoded finding SK (api%23{id}). firstSeen is Unix epoch milliseconds. affectedResources is an array of { name, type, tags } (max 3 tags per asset). Idempotency-Key is required. The same key and payload replays the stored 2xx for 24 hours. Requires scope vulnerability:write.

curl -X POST "https://api.scrut.io/v1/vulnerabilities" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: 7c9e6679-7425-40de-944b-e07fc1f90ae7" \
  -H "Authorization: Bearer YOUR_API_TOKEN (JWT)" \
  -d '{
  "vulnerabilityId": "VUL-5672",
  "title": "Public S3 bucket",
  "description": "Bucket is world-readable.",
  "remediation": "Block public ACLs.",
  "stepsToReproduce": "Open the bucket URL.",
  "severity": "high",
  "status": "open",
  "fixAvailable": "no",
  "firstSeen": 1704067200000,
  "affectedResources": [
    {
      "name": "s3://bucket",
      "type": "s3",
      "tags": [
        "public",
        "prod"
      ]
    }
  ],
  "assigneeEmail": "jordan@example.com"
}'
{
  "data": {
    "vulnerabilityId": "api%23VUL-5672",
    "title": "Public S3 bucket",
    "description": "Bucket is world-readable.",
    "status": "open",
    "severity": "high",
    "source": "api",
    "assignees": [
      {
        "name": "Jordan Kim",
        "email": "jordan@example.com",
        "isPrimary": true
      }
    ],
    "firstSeen": 1704067200000,
    "cveId": "",
    "affectedResources": [
      {
        "name": "s3://bucket",
        "type": "s3",
        "tags": [
          "public",
          "prod"
        ]
      }
    ],
    "remediation": "Block public ACLs.",
    "stepsToReproduce": "Open the bucket URL.",
    "customFields": []
  },
  "meta": {
    "requestId": "550e8400-e29b-41d4-a716-446655440000"
  }
}
POST
/v1/vulnerabilities
POST
Base URLstring

Target server for requests. Edit to use your own host.

Bearer Token (JWT)
Bearer Tokenstring
Required

Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.

Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.
Content-Typestring
Required

The media type of the request body

Options: application/json
header
Idempotency-Keystring
Required

Client-generated key identifying one logical write. 1–128 characters; letters, numbers, and . _ ~ - only. Reuse the same key and body to retry safely. Reusing a key with a different body returns 409 idempotency_key_reused. Successful 2xx responses are replayed for 24 hours.

Min length: 1 • Max length: 128 • Pattern: ^[A-Za-z0-9._~-]{1,128}$
vulnerabilityIdstring
Required

CVE id or VUL- followed by four digits. The stored SK is import#{vulnerabilityId}.

Pattern: ^(VUL-\d{4}|CVE-\d{4}-(0\d{3}|[1-9]\d{3,}))$
descriptionstring
Max length: 750
remediationstring
Max length: 750
stepsToReproducestring
Max length: 750
severitystring
Required
Options: critical, high, medium, low
statusstring
Required
Options: open, closed, acknowledged
fixAvailablestring
Options: yes, no
firstSeeninteger

Unix epoch milliseconds.

Format: int64
assigneeEmailstring
Format: email
Request Preview
Response

Response will appear here after sending the request

Authentication

header
Authorizationstring
Required

Bearer token (JWT). Machine access token from POST /oauth/token. Send Authorization: Bearer $SCRUT_ACCESS_TOKEN on every /v1 request.

Headers

Idempotency-Keystring
Required

Client-generated key identifying one logical write. 1–128 characters; letters, numbers, and . _ ~ - only. Reuse the same key and body to retry safely. Reusing a key with a different body returns 409 idempotency_key_reused. Successful 2xx responses are replayed for 24 hours.

Example:
7c9e6679-7425-40de-944b-e07fc1f90ae7

Body

application/json
vulnerabilityIdstring
Required

CVE id or VUL- followed by four digits. The stored SK is import#\\{vulnerabilityId\\}.

Example:
VUL-5672
titlestring
Required
Example:
Public S3 bucket
descriptionstring
Example:
Bucket is world-readable.
remediationstring
Example:
Block public ACLs.
stepsToReproducestring
Example:
Open the bucket URL.
severitystring
Required
Allowed values:criticalhighmediumlow
statusstring
Required
Allowed values:openclosedacknowledged
fixAvailablestring
Allowed values:yesno
firstSeeninteger

Unix epoch milliseconds.

Example:
1704067200000
assigneeEmailstring
Example:
jordan@example.com

Responses