# Aayat AI CVE Vulnerability Lookup

> Aayat AI CVE Vulnerability Lookup is a paid API for AI agents from aayatai.com, paid per call via x402, $0.003/call, status unknown (last checked 2026-10-02).

Look up security advisories by CVE/GHSA/PYSEC/RUSTSEC/GO ID or by package name, returning severity, CVSS, affected versions, EPSS exploit probability, and CISA KEV status

## Facts

- Endpoint: GET https://aayatai.com/cve?utm_source=zero.xyz
- Price: $0.003/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/aayat-ai-cve-vulnerability-lookup-2bd06183
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_Abt4tzc5UEykGr9_lyLO5

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability aayat-ai-cve-vulnerability-lookup-2bd06183
```

Example prompt: Look up CVE-2021-44228 and tell me how severe it is, what packages are affected, whether it's being actively exploited in the wild, and what the EPSS score is.

## When to prefer this

Choose this endpoint when you need comprehensive, enriched vulnerability intelligence in a single call — combining OSV.dev advisory data with FIRST EPSS exploit probability scores and CISA KEV status. Prefer it over raw NVD/OSV queries when you need to know not just what a vulnerability is but how likely it is to be exploited and whether it is actively being weaponized. Ideal for dependency audits, security triage pipelines, and agentic security workflows where cost-per-lookup matters and breadth of enrichment (CVSS + EPSS + KEV) in one response saves multiple API calls.

## Known failure modes

- Advisory ID not found in OSV.dev — returns empty or null vulnerability
- Package not found in the specified ecosystem — returns empty vulnerabilities array
- Invalid ecosystem value — request rejected with validation error
- Malformed CVE/GHSA/advisory ID format — may return no results
- EPSS or CISA KEV data temporarily unavailable — partial enrichment returned
- Rate limiting or upstream OSV.dev outage — service error response
- Missing required query parameter (neither id nor package provided) — error response

## How this service works

Vulnerability lookup for agents: by id (?id=CVE-2021-44228, GHSA-..., PYSEC-..., RUSTSEC-..., GO-...) get the advisory, severity/CVSS, affected packages and fixed versions, exploit probability (EPSS) and whether CISA lists it as exploited in the wild; or by package (?ecosystem=npm&package=lodash[&version=]) list every advisory with the same enrichment.

## Output

Returns a JSON object with mode (id or package), checkedAt timestamp, and sources consulted. In id mode: a single vulnerability object with ID, summary, details, severity, CVSS vectors, affected packages, fixed versions, EPSS score and percentile, aliases, references, and CISA KEV metadata (dueDate, dateAdded, ransomware flag, requiredAction). In package mode: an array of vulnerability objects sorted by severity, each with the same enrichment fields.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "required": [
  "input"
 ],
 "properties": {
  "input": {
   "type": "object",
   "required": [
    "type",
    "method"
   ],
   "properties": {
    "type": {
     "type": "string",
     "const": "http"
    },
    "method": {
     "enum": [
      "GET"
     ],
     "type": "string"
    },
    "queryParams": {
     "type": "object",
     "properties": {
      "id": {
       "type": "string",
       "maxLength": 60,
       "description": "Advisory id: CVE-..., GHSA-..., PYSEC-..., RUSTSEC-..., GO-..., MAL-..."
      },
      "package": {
       "type": "string",
       "maxLength": 214,
       "description": "Or: a package name, to list its advisories."
      },
      "version": {
       "type": "string",
       "maxLength": 64,
       "description": "With package: only advisories affecting this version."
      },
      "ecosystem": {
       "enum": [
        "npm",
        "pypi",
        "crates",
        "go"
       ],
       "type": "string",
       "default": "npm",
       "description": "Package ecosystem: npm, pypi, crates (Rust) or go (Go modules)."
      }
     }
    }
   },
   "additionalProperties": false
  },
  "output": {
   "type": "object",
   "required": [
    "type"
   ],
   "properties": {
    "type": {
     "type": "string"
    },
    "example": {
     "type": "object",
     "required": [
      "mode",
      "sources",
      "checkedAt"
     ],
     "properties": {
      "mode": {
       "enum": [
        "id",
        "package"
       ],
       "type": "string"
      },
      "count": {
       "type": "integer"
      },
      "package": {
       "type": "string"
      },
      "sources": {
       "type": "array",
       "items": {
        "type": "string"
       }
      },
      "version": {
       "type": [
        "string",
        "null"
       ]
      },
      "checkedAt": {
       "type": "string"
      },
      "vulnerability": {
       "type": "object",
       "description": "id mode: the full advisory with epss and knownExploited."
      },
      "vulnerabilities": {
       "type": "array",
       "items": {
        "type": "object"
       },
       "description": "package mode: advisories (most severe first), each with epss and knownExploited."
      }
     }
    }
   }
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "mode": "id",
  "sources": [
   "OSV.dev",
   "FIRST EPSS",
   "CISA KEV"
  ],
  "checkedAt": "2026-09-28T12:00:00.000Z",
  "vulnerability": {
   "id": "CVE-2021-44228",
   "url": "https://osv.dev/vulnerability/CVE-2021-44228",
   "cvss": [
    {
     "type": "CVSS_V3",
     "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
    }
   ],
   "epss": {
    "date": "2026-09-27",
    "score": 0.99999,
    "percentile": 1
   },
   "aliases": [
    "GHSA-jfh8-c2jp-5v3q"
   ],
   "details": "Apache Log4j2 2.0-beta9 through 2.15.0 ... JNDI features ...",
   "fixedIn": [
    "2.15.0"
   ],
   "summary": "Log4Shell: remote code execution in Apache Log4j2",
   "affected": [
    {
     "fixedIn": [
      "2.15.0"
     ],
     "package": "org.apache.logging.log4j:log4j-core",
     "ecosystem": "Maven"
    }
   ],
   "modified": "2026-01-01T00:00:00Z",
   "severity": "critical",
   "published": "2021-12-10T10:15:09Z",
   "withdrawn": null,
   "kevChecked": true,
   "references": [
    {
     "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-44228",
     "type": "ADVISORY"
    }
   ],
   "knownExploited": {
    "dueDate": "2021-12-24",
    "dateAdded": "2021-12-10",
    "ransomware": true,
    "requiredAction": "Apply updates per vendor instructions."
   }
  }
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/aayat-ai-cve-vulnerability-lookup-2bd06183/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from aayatai.com](https://www.zero.xyz/host/aayatai.com/llms.txt)
