List vulnerabilities
Returns current vulnerabilities. Filters apply together. runId selects vulnerabilities discovered or worked on during that run, including subsequent verification; their current status and assignment are returned. The SDK’s run.vulnerabilities.list() method supplies this filter. A referenced run or vulnerability outside your organization returns 404.
curl --request GET \
--url https://api.antigen.sh/v1/vulnerabilities \
--header 'x-api-key: <api-key>'import requests
url = "https://api.antigen.sh/v1/vulnerabilities"
headers = {"x-api-key": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {'x-api-key': '<api-key>'}};
fetch('https://api.antigen.sh/v1/vulnerabilities', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.antigen.sh/v1/vulnerabilities",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"x-api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.antigen.sh/v1/vulnerabilities"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("x-api-key", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.antigen.sh/v1/vulnerabilities")
.header("x-api-key", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.antigen.sh/v1/vulnerabilities")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["x-api-key"] = '<api-key>'
response = http.request(request)
puts response.read_body[
{
"id": "vuln_123",
"title": "Cross-account invoice access",
"description": "An authenticated account can retrieve another account’s invoice by changing its ID.",
"severity": "high",
"target": "api.example.com",
"runId": "run_123",
"remediation": "Check that the authenticated account owns the invoice before returning it.",
"status": "open",
"assignee": null,
"riskAcceptance": null,
"createdAt": "2026-09-13T10:00:00.000Z",
"updatedAt": "2026-09-13T10:00:00.000Z"
}
]{
"error": {
"code": "invalid_request",
"message": "Check the request fields and values."
}
}{
"error": {
"code": "unauthorized",
"message": "Supply a valid API key."
}
}{
"error": {
"code": "forbidden",
"message": "The API key does not permit this operation or requested scope."
}
}{
"error": {
"code": "not_found",
"message": "The resource does not exist in this organization."
}
}{
"error": {
"code": "rate_limited",
"message": "Retry after the interval in Retry-After."
}
}Authorizations
API key from your organization. Supply the value directly, without a Bearer prefix.
Query Parameters
Run associated with the vulnerabilities.
1Severity.
critical, high, medium, low Lifecycle status.
open, in_progress, remediated, verified, accepted_risk Response
Successful response.
1Short description of the weakness.
1Affected behavior, reproduction steps, and impact.
1critical, high, medium, low Proposed remediation steps. May include links to pull requests or infrastructure recommendations.
Run that originally discovered the vulnerability, if any.
open, in_progress, remediated, verified, accepted_risk Team member email or registered agent name. Null means unassigned.
Show child attributes
Show child attributes
curl --request GET \
--url https://api.antigen.sh/v1/vulnerabilities \
--header 'x-api-key: <api-key>'import requests
url = "https://api.antigen.sh/v1/vulnerabilities"
headers = {"x-api-key": "<api-key>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {'x-api-key': '<api-key>'}};
fetch('https://api.antigen.sh/v1/vulnerabilities', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.antigen.sh/v1/vulnerabilities",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"x-api-key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.antigen.sh/v1/vulnerabilities"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("x-api-key", "<api-key>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.antigen.sh/v1/vulnerabilities")
.header("x-api-key", "<api-key>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.antigen.sh/v1/vulnerabilities")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["x-api-key"] = '<api-key>'
response = http.request(request)
puts response.read_body[
{
"id": "vuln_123",
"title": "Cross-account invoice access",
"description": "An authenticated account can retrieve another account’s invoice by changing its ID.",
"severity": "high",
"target": "api.example.com",
"runId": "run_123",
"remediation": "Check that the authenticated account owns the invoice before returning it.",
"status": "open",
"assignee": null,
"riskAcceptance": null,
"createdAt": "2026-09-13T10:00:00.000Z",
"updatedAt": "2026-09-13T10:00:00.000Z"
}
]{
"error": {
"code": "invalid_request",
"message": "Check the request fields and values."
}
}{
"error": {
"code": "unauthorized",
"message": "Supply a valid API key."
}
}{
"error": {
"code": "forbidden",
"message": "The API key does not permit this operation or requested scope."
}
}{
"error": {
"code": "not_found",
"message": "The resource does not exist in this organization."
}
}{
"error": {
"code": "rate_limited",
"message": "Retry after the interval in Retry-After."
}
}