Vulnerability Management
Vulnerability management in Hashiro centers around issues: individual security findings discovered during assessments. Each issue captures the full lifecycle of a vulnerability from discovery through remediation.

Screenshots use fictional demonstration data.
Creating Issues
Issues can be created in several ways:
- Manually: pentesters create findings using the issue editor
- From templates: use a vulnerability template as a starting point
- Automated scanning: Nuclei-based scans generate findings
- AI assessments: the AI engine discovers and reports findings as candidates
Issue Detail
| Field | Description |
|---|---|
| Title | Clear, descriptive name for the vulnerability |
| Description | Detailed explanation of the vulnerability and its context |
| Severity | Critical, High, Medium, Low, or Informative |
| CVSS v3.1 | Standardized scoring with full vector string |
| Status | Current lifecycle state (see Issue Lifecycle) |
| Asset | The affected host, URL, or service |
| Observation | What was observed during testing |
| Demonstration | Step-by-step proof of exploitation |
| Remediation | Recommended fix or mitigation |
| References | External links (CVEs, advisories, documentation) |
| Evidence | Screenshots, payloads, and response captures |
Edit Mode
The issue editor is organized into tabs:
- Basic Info: title, description, severity, status, asset, category
- CVSS / Impact: CVSS v3.1 calculator and impact assessment
- Additional Info: remediation, references, observation, demonstration

Attachments
Issues support file uploads for evidence: screenshots, request/response captures, payloads, and supporting documentation.
History Timeline
Every issue maintains an immutable audit trail of all changes: status transitions, severity changes, retest results, and who made each change.
Navigation
The other-findings drawer lets you quickly switch between issues in the same project without returning to the issues list.
Nuclei Scan Results
Issues from automated Nuclei scanning appear in a dedicated view with paginated results, severity classification, and direct issue creation from scan results.