Home / Companies / Lakera / Blog / Post Details
Content Deep Dive

Why We Need OWASP's AIVSS: Extending CVSS for the Agentic AI Era

Blog post from Lakera

Post Details
Company
Date Published
Author
Steve Giguere
Word Count
1,300
Company Posts That Month
138
Language
-
Hacker News Points
-
Post removed?
No
Summary

OWASP's Agentic AI Vulnerability Scoring System (AIVSS) has been developed to address the inadequacies of the Common Vulnerability Scoring System (CVSS) in evaluating risks associated with AI agents. While CVSS serves as a foundational tool for assessing vulnerability severity, it struggles with the dynamic and unpredictable nature of agentic systems where AI agents can act, improvise, and potentially conspire. AIVSS enhances CVSS by introducing an Agentic AI Risk Score (AARS), which factors in the amplification effects of AI autonomy, memory, and multi-agent interactions, and a Threat Multiplier to adjust scores based on active exploits. This enhanced system maintains the familiar 0-10 scoring range but provides a more accurate reflection of risks in AI contexts, enabling security teams to better prioritize vulnerabilities. Lakera, involved in shaping AIVSS, emphasizes its practicality in real-world scenarios, bridging the gap between traditional security measures and the evolving challenges posed by AI technologies.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
AI Agents 11 3,474 677 184 +12%
Multi-agent systems 4 261 87 52 +14%
LLM 1 5,556 752 184 +14%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.