{"schemaVersion":"1.0","caseId":"cisa-vulnrichment-333","canonicalUrl":"https://hermes-labs.ai/case-studies/cisa-vulnrichment-score-consistency","title":"Hermes Labs CISA CVSS Consistency Correction","status":"acknowledged-and-corrected","dates":{"published":"2026-09-08","modified":"2026-09-08"},"subject":{"cve":"CVE-2026-14216","snapshot":"b4481a9ea6cbb1e36ba9a746ef29de45b95567f8","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","storedScore":5.3,"calculatedScore":6.5,"severityBefore":"MEDIUM","severityAfter":"MEDIUM"},"audit":{"repositoryRecordsExamined":178776,"eligibleRecentCisaAdpRecords":5324,"cvss3MetricsChecked":1060,"cweAssignmentsChecked":1634,"ssvcBlocksChecked":5324,"deterministicMismatches":1,"evidenceClass":"publisher-held-summary","originalSessionId":"01a060ef-7319-7bb3-867c-40f86100a78f","originalResultSha256":"463f28d4ba2e3bdb2eadc81758d0cb80481ab40565b616653a2fe22d1c51d6ce","replayedForPublication":false},"trace":[{"id":"mandate","at":"2026-09-02T07:05:05.155Z","actor":"owner","action":"Issued a broad world-state mandate with an independently observable evidence requirement.","evidenceClass":"publisher-held-summary"},{"id":"bounded-control","at":"2026-09-02T19:48:14.550Z","actor":"owner","action":"Authorized a coordinator to take obvious bounded next actions while prohibiting scope expansion.","evidenceClass":"publisher-held-summary"},{"id":"audit-selected","at":"2026-09-02T19:49:29Z","actor":"hermes-labs-system","action":"Selected the CISA Vulnrichment audit from at most three candidates using deterministic validation and public-correction criteria.","evidenceClass":"publisher-held-summary"},{"id":"audit-launched","at":"2026-09-02T19:50:21.941Z","actor":"coordinator","action":"Continued the selected audit for local and read-only work while keeping external mutations parked.","evidenceClass":"publisher-held-summary"},{"id":"scope-frozen","at":"2026-09-02T19:50:42Z","actor":"hermes-labs-system","action":"Froze a 14-day snapshot audit, deterministic validators, exclusions, and a conditional null-yield expansion rule.","evidenceClass":"publisher-held-summary"},{"id":"finding","at":"2026-09-02T19:56:50Z","actor":"hermes-labs-system","action":"Found one score/vector mismatch in CVE-2026-14216 and reproduced the 6.5 calculation.","evidenceClass":"publisher-held-summary"},{"id":"self-correction","at":"2026-09-02T19:59:26Z","actor":"hermes-labs-system","action":"Withdrew an unsupported history inference and narrowed the proposed correction language.","evidenceClass":"publisher-held-summary"},{"id":"authorization","at":"2026-09-02T20:19:49.376Z","actor":"owner","action":"Authorized the exact filing target and account and directed the system not to expand the audit for an artificial holdout.","evidenceClass":"publisher-held-summary"},{"id":"issue-opened","at":"2026-09-02T20:21:09Z","actor":"roli-lpci","action":"Opened cisagov/vulnrichment issue #333 with the reproduced inconsistency.","evidenceClass":"public","citation":"https://github.com/cisagov/vulnrichment/issues/333"},{"id":"public-correction","at":"2026-09-03T13:01:39Z","actor":"official CVE corpus","action":"The official CVE corpus recorded the numeric correction from 5.3 to 6.5.","evidenceClass":"public","citation":"https://github.com/CVEProject/cvelistV5/commit/fa52a90c974f64966065f0beb9f4ffcefaf1208f"},{"id":"cisa-acknowledgement","at":"2026-09-03T13:05:08Z","actor":"CISA","action":"Thanked the reporter, confirmed the republished 6.5 score, and closed the issue.","evidenceClass":"public","citation":"https://github.com/cisagov/vulnrichment/issues/333#issuecomment-5526230961"},{"id":"vulnrichment-sync","at":"2026-09-03T13:16:17Z","actor":"CISA","action":"Vulnrichment synchronized the refreshed upstream record in its data-update commit.","evidenceClass":"public","citation":"https://github.com/cisagov/vulnrichment/commit/4dad1386622ef620991b1f7e886a92a9fd9c7d73"}],"evidenceClasses":{"public":"Independently accessible primary-source record.","publisher-held-summary":"Summary of the publisher-held execution record; raw session material is not published."},"artifact":{"url":"https://github.com/hermes-labs-ai/hermes-labs-cvss-consistency","commit":"d16f9060ad3a532d1938e62fdbfb84d55285eaef","immutableUrl":"https://github.com/hermes-labs-ai/hermes-labs-cvss-consistency/tree/d16f9060ad3a532d1938e62fdbfb84d55285eaef","postEventReusableImplementation":true,"relationToOriginalRun":"The repository preserves the recovered original scanner separately and provides a reviewed reusable checker. Fixture replay is not the original corpus audit."},"originalRuntime":{"application":"Codex Desktop 0.152.0","provider":"OpenAI","model":"gpt-5.6-sol","reasoningEffort":"medium","evidenceClass":"publisher-held-summary","sourceSessionId":"01a060ef-7319-7bb3-867c-40f86100a78f"},"citations":["https://github.com/cisagov/vulnrichment/issues/333","https://github.com/cisagov/vulnrichment/issues/333#issuecomment-5526230961","https://github.com/CVEProject/cvelistV5/commit/fa52a90c974f64966065f0beb9f4ffcefaf1208f","https://github.com/cisagov/vulnrichment/commit/4dad1386622ef620991b1f7e886a92a9fd9c7d73","https://www.first.org/cvss/v3.1/specification-document","https://github.com/hermes-labs-ai/hermes-labs-cvss-consistency","https://github.com/hermes-labs-ai/hermes-labs-cvss-consistency/tree/d16f9060ad3a532d1938e62fdbfb84d55285eaef"],"limitations":["This was a consistency correction, not a new vulnerability discovery.","The Medium severity category did not change.","The public record does not establish a general safety property for autonomous agents."]}