OWASP Introduces AI Vulnerability Scoring System for Emerging Threats
At the OWASP Global AppSec conference, the organization unveiled the AI Vulnerability Scoring System (AIVSS), a new framework designed to measure risks specific to autonomous and agentic AI systems. Building on traditional scoring models, AIVSS incorporates factors like autonomy, non-determinism, tool use, and dynamic identity. It addresses challenges such as transient AI agent identities and new attack vectors including tool misuse, cascading agent failures, context manipulation, and instruction tampering. The framework is in draft form, with version 1.0 expected next year. scworld.com/resource/owasp-global-appsec-new-ai-vulnerability-scoring-system-unveiled