> For the complete documentation index, see [llms.txt](https://docs.ox.security/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.ox.security/api-documentation/api-reference/api--issue/types/objects/sca-vulnerability.md).

# scaVulnerability

Details of a Software Composition Analysis (SCA) vulnerability.

### Examples

```graphql
type SCAVulnerability {
  issueId: String
  oxSeverity: String
  severityNumberFromTool: String
  severityFromTool: String
  cve: String
  cveLink: String
  cvsVer: String
  cvssVersion: Float
  epss: Float
  percentile: Float
  libName: String
  dependencyChain: String
  runtimeStatus: String
  runtimeContext: RuntimeInfo
  libVersion: String
  chainDepth: Int
  exploitInTheWild: Boolean
  exploitInTheWildLink: String
  description: String
  dateDiscovered: String
  minorVerWithFix: String
  majorVerWithFix: String
  exploitRequirement: String
  exploitCode: String
  originalSeverity: String
}
```

### Fields

| Field                                                                                                     | Description                                             | Supported fields                                                                                                                   |
| --------------------------------------------------------------------------------------------------------- | ------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- |
| issueId `String`                                                                                          | ID of the related issue                                 |                                                                                                                                    |
| oxSeverity `String`                                                                                       | Severity according to the OX scoring system             |                                                                                                                                    |
| severityNumberFromTool `String`                                                                           | Severity number as reported by the scanning tool        |                                                                                                                                    |
| severityFromTool `String`                                                                                 | Severity description as reported by the scanning tool   |                                                                                                                                    |
| cve `String`                                                                                              | CVE identifier                                          |                                                                                                                                    |
| cveLink `String`                                                                                          | URL link to detailed CVE information                    |                                                                                                                                    |
| cvsVer `String`                                                                                           | Version of the CVS standard used                        |                                                                                                                                    |
| cvssVersion `Float`                                                                                       | Version number of the CVSS standard used                |                                                                                                                                    |
| epss `Float`                                                                                              | Exploit Prediction Scoring System (EPSS) score          |                                                                                                                                    |
| percentile `Float`                                                                                        | Percentile ranking of the vulnerability                 |                                                                                                                                    |
| libName `String`                                                                                          | Name of the vulnerable library                          |                                                                                                                                    |
| dependencyChain `String`                                                                                  | Dependency chain leading to the vulnerable library      |                                                                                                                                    |
| runtimeStatus `String`                                                                                    | Runtime status of the library                           |                                                                                                                                    |
| runtimeContext [`RuntimeInfo`](/api-documentation/api-reference/api--issue/types/objects/runtime-info.md) | Runtime information including status and cloud contexts | <p>runtimeStatus <code>String</code><br>cloudContexts <a href="/pages/ex3B0I01j8LJ8r9HlQNY"><code>\[RuntimeContext]</code></a></p> |
| libVersion `String`                                                                                       | Version of the vulnerable library                       |                                                                                                                                    |
| chainDepth `Int`                                                                                          | Depth level in the dependency chain                     |                                                                                                                                    |
| exploitInTheWild `Boolean`                                                                                | Indicates if an exploit exists in the wild              |                                                                                                                                    |
| exploitInTheWildLink `String`                                                                             | URL to exploit details if available                     |                                                                                                                                    |
| description `String`                                                                                      | Description of the vulnerability                        |                                                                                                                                    |
| dateDiscovered `String`                                                                                   | Date when the vulnerability was discovered              |                                                                                                                                    |
| minorVerWithFix `String`                                                                                  | Minor version of the library that includes a fix        |                                                                                                                                    |
| majorVerWithFix `String`                                                                                  | Major version of the library that includes a fix        |                                                                                                                                    |
| exploitRequirement `String`                                                                               | Requirements for exploiting the vulnerability           |                                                                                                                                    |
| exploitCode `String`                                                                                      | Code or technique used for exploit                      |                                                                                                                                    |
| originalSeverity `String`                                                                                 | Original severity rating of the vulnerability           |                                                                                                                                    |

### References

#### Fields with this object:

* [{} SbomLib.vulnerabilities](/api-documentation/api-reference/api--issue/types/objects/sbom-lib.md)
* [{} Issue.scaVulnerabilities](/api-documentation/api-reference/api--issue/types/objects/issue.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.ox.security/api-documentation/api-reference/api--issue/types/objects/sca-vulnerability.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
