Skip to content

Vulnerability Management ​

Vulnerability management in Hashiro centers around issues: individual security findings discovered during assessments. Each issue captures the full lifecycle of a vulnerability from discovery through remediation.

Issue detail view

Screenshots use fictional demonstration data.

Creating Issues ​

Issues can be created in several ways:

  • Manually: pentesters create findings using the issue editor
  • From templates: use a vulnerability template as a starting point
  • Automated scanning: Nuclei-based scans generate findings
  • AI assessments: the AI engine discovers and reports findings as candidates

Issue Detail ​

FieldDescription
TitleClear, descriptive name for the vulnerability
DescriptionDetailed explanation of the vulnerability and its context
SeverityCritical, High, Medium, Low, or Informative
CVSS v3.1Standardized scoring with full vector string
StatusCurrent lifecycle state (see Issue Lifecycle)
AssetThe affected host, URL, or service
ObservationWhat was observed during testing
DemonstrationStep-by-step proof of exploitation
RemediationRecommended fix or mitigation
ReferencesExternal links (CVEs, advisories, documentation)
EvidenceScreenshots, payloads, and response captures

Edit Mode ​

The issue editor is organized into tabs:

  • Basic Info: title, description, severity, status, asset, category
  • CVSS / Impact: CVSS v3.1 calculator and impact assessment
  • Additional Info: remediation, references, observation, demonstration

Issue editor tabs

Attachments ​

Issues support file uploads for evidence: screenshots, request/response captures, payloads, and supporting documentation.

History Timeline ​

Every issue maintains an immutable audit trail of all changes: status transitions, severity changes, retest results, and who made each change.

The other-findings drawer lets you quickly switch between issues in the same project without returning to the issues list.

Nuclei Scan Results ​

Issues from automated Nuclei scanning appear in a dedicated view with paginated results, severity classification, and direct issue creation from scan results.

Hashiro. Continuous Threat Exposure Management.