This endpoint returns package-level CVE and GHSA findings across every Bill of Materials in your tenant, so you can integrate Cranium's findings with vulnerability management tools like ServiceNow VR or Avalar.
List Technology Vulnerabilities
Returns a paginated list of technology vulnerabilities: package-level CVE and GHSA findings across all Bills of Materials in your tenant. This endpoint covers technology vulnerabilities only. For model vulnerability findings (attack categories from Cranium Arena), see the Arena Model Vulnerabilities endpoint reference.
Request
GET /api/public/vulnerabilities
Authentication
Bearer token. See Authentication & Generating Credentials.
Required Permission
Api_Vulnerabilities_Read
Query Parameters

Response Fields

Sample Response
{
"data": [
{
"uniqueId": "b7c8d9e0-1a2b-3c4d-5e6f-7a8b9c0d1e2f",
"knownVulnerabilityId": "c8d9e0f1-2b3c-4d5e-6f7a-8b9c0d1e2f3a",
"billOfMaterialsId": "a1b2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d",
"billOfMaterialsName": "my-ml-service",
"aiSystemIds": ["a2d78b6f-9c4c-4a7d-d16f-4e1d8c9b0f20"],
"packageName": "numpy",
"packageVersion": "1.21.0",
"issueId": "GHSA-abcd-1234-efgh",
"cveId": "CVE-2024-1234",
"summary": "Buffer overflow in numpy array handling",
"source": "OSV",
"sourceUrl": "https://osv.dev/vulnerability/GHSA-abcd-1234-efgh",
"cvssSeverity": "Critical",
"cvssScore": 9.8,
"fixedVersion": "1.24.0",
"discoveryDate": "2026-01-10T08:00:00Z",
"resolvedDate": null,
"resolvedStatus": null,
"updatedAt": "2026-04-01T00:00:00Z"
}
],
"pagination": {
"limit": 100,
"nextCursor": "eyJ1cGRhdGVkQXQiOiIyMDI2LTA0LTAxVDAwOjAwOjAwWiIsImlkIjoiYjdjOGQ5ZTAifQ==",
"hasMore": false
},
"error": null,
"meta": {
"requestId": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"timestamp": "2026-08-24T10:05:00Z"
}
}
uniqueId is a stable composite key; treat it as opaque and us it for deduplication rather than parsing it. issueId is the identifier as originally reported by OSV and may be a CVE, GHSA, or PYSEC identifier; cveId is always CVE-format when populated, so use cveId rather than issueId when correlating with CVE-keyed systems like ServiceNow VR. resolvedStatus reflects user-actioned resolution only, and only for vulnerabilities still present in the current Bill of Materials. Unlike the UI and CSV export, this endpoint returns resolved and ignored vulnerabilities too, so filter on resolvedStatus: null if you want parity with what's shown on the platform.
When a package is updated or removed, its vulnerabilities are dropped from the feed entirely rather than marked resolved. This drop does not advance updatedAt, so incremental cursor-based polling will not catch it. To detect closed vulnerabilities, run a periodic full sync without a cursor and treat anything missing from that sync as closed.
Error Responses
400 VALIDATION_FAILED: the cursor is invalid, orcursorandupdatedAfterwere supplied together.401 UNAUTHORIZED: the request is missing a token, or the token lacksApi_Vulnerabilities_Read.500 INTERNAL_ERROR: an unexpected server error.





