> ## Documentation Index
> Fetch the complete documentation index at: https://docs.antigen.sh/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Update a vulnerability

> Updates status, assignee, and riskAcceptance atomically. Technical findings and remediation content are maintained through authorized agent tools. Omitted fields retain their values. Assign a team member by email or an agent by its registered name; use null to unassign. Moving to in_progress requires an assignee, which can be included in the same request.

Set remediated after the fix is deployed. With the default verification hook enabled, this starts verification. The verified status is set through verification and cannot be assigned directly here. Accepting risk requires riskAcceptance with a note and future expiresAt. Moving away from accepted_risk clears riskAcceptance.

Changes to status or assignee emit their respective events after the update is saved. Sending an unchanged value emits no event. Work started by hooks runs separately. The SDK’s updateStatus() and updateAssignee() methods call this endpoint.



## OpenAPI

````yaml /reference/openapi.yaml patch /vulnerabilities/{id}
openapi: 3.1.0
info:
  title: Antigen API
  version: v1
  description: >-
    Work with the same agents, runs, and resources your team uses in Antigen.
    Requests and responses use camelCase fields. List endpoints return arrays.
    See the [overview](/reference) for authentication, updates, and errors.
servers:
  - url: https://api.antigen.sh/v1
security:
  - ApiKeyAuth: []
tags:
  - name: Agents
    description: Retrieve, compose, and register agent configurations.
  - name: Models
    description: Models available to agents in your organization.
  - name: Targets
    description: Submit testing scope for human approval.
  - name: Runs
    description: Execute agents and control their work.
  - name: Vulnerabilities
    description: Track weaknesses, remediation, status, and assignment.
  - name: Evidence
    description: Read supporting file metadata and retrieve file contents.
  - name: Reports
    description: Read and export captured engagement results.
  - name: Human tasks
    description: Ask people for help and follow their responses.
  - name: Hooks
    description: Connect status and assignment changes to your own service.
  - name: Asset Map
    description: Read your organization’s infrastructure graph.
  - name: Integrations
    description: Inspect and disconnect provider connections.
  - name: API keys
    description: Create and revoke credentials for automation.
paths:
  /vulnerabilities/{id}:
    patch:
      tags:
        - Vulnerabilities
      summary: Update a vulnerability
      description: >-
        Updates status, assignee, and riskAcceptance atomically. Technical
        findings and remediation content are maintained through authorized agent
        tools. Omitted fields retain their values. Assign a team member by email
        or an agent by its registered name; use null to unassign. Moving to
        in_progress requires an assignee, which can be included in the same
        request.


        Set remediated after the fix is deployed. With the default verification
        hook enabled, this starts verification. The verified status is set
        through verification and cannot be assigned directly here. Accepting
        risk requires riskAcceptance with a note and future expiresAt. Moving
        away from accepted_risk clears riskAcceptance.


        Changes to status or assignee emit their respective events after the
        update is saved. Sending an unchanged value emits no event. Work started
        by hooks runs separately. The SDK’s updateStatus() and updateAssignee()
        methods call this endpoint.
      operationId: updateVulnerability
      parameters:
        - name: id
          in: path
          required: true
          description: Opaque resource identifier.
          schema:
            type: string
            minLength: 1
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UpdateVulnerability'
            examples:
              assign:
                value:
                  assignee: remediation-agent
              begin:
                value:
                  assignee: alex@example.com
                  status: in_progress
              verify:
                value:
                  status: remediated
              acceptRisk:
                value:
                  status: accepted_risk
                  riskAcceptance:
                    note: >-
                      The affected service will be retired before this review
                      expires.
                    expiresAt: '2027-01-01T00:00:00.000Z'
      responses:
        '200':
          description: Successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Vulnerability'
        '400':
          $ref: '#/components/responses/Error400'
        '401':
          $ref: '#/components/responses/Error401'
        '403':
          $ref: '#/components/responses/Error403'
        '404':
          $ref: '#/components/responses/Error404'
        '409':
          $ref: '#/components/responses/Error409'
        '429':
          $ref: '#/components/responses/Error429'
components:
  schemas:
    UpdateVulnerability:
      type: object
      properties:
        status:
          type: string
          description: verified is set by verification, not by this endpoint.
          enum:
            - open
            - in_progress
            - remediated
            - accepted_risk
        assignee:
          type:
            - string
            - 'null'
          description: >-
            Team member email, registered agent name, or null to remove the
            assignment.
        riskAcceptance:
          $ref: '#/components/schemas/RiskAcceptance'
      required: []
      additionalProperties: false
      minProperties: 1
      allOf:
        - if:
            required:
              - status
            properties:
              status:
                const: accepted_risk
          then:
            required:
              - riskAcceptance
      example:
        assignee: remediation-agent
      description: >-
        Updates workflow fields only. Technical findings and remediation content
        are maintained through authorized agent tools.
    Vulnerability:
      type: object
      properties:
        id:
          type: string
          minLength: 1
        title:
          type: string
          description: Short description of the weakness.
          minLength: 1
        description:
          type: string
          description: Affected behavior, reproduction steps, and impact.
          minLength: 1
        severity:
          type: string
          enum:
            - critical
            - high
            - medium
            - low
        remediation:
          type: string
          description: >-
            Proposed remediation steps. May include links to pull requests or
            infrastructure recommendations.
        target:
          type: string
        runId:
          type:
            - string
            - 'null'
          description: Run that originally discovered the vulnerability, if any.
        status:
          type: string
          enum:
            - open
            - in_progress
            - remediated
            - verified
            - accepted_risk
        assignee:
          type:
            - string
            - 'null'
          description: Team member email or registered agent name. Null means unassigned.
        riskAcceptance:
          oneOf:
            - $ref: '#/components/schemas/RiskAcceptance'
            - type: 'null'
        createdAt:
          type: string
          format: date-time
        updatedAt:
          type: string
          format: date-time
      required:
        - id
        - title
        - description
        - severity
        - remediation
        - target
        - runId
        - status
        - assignee
        - riskAcceptance
        - createdAt
        - updatedAt
      additionalProperties: false
      example:
        id: vuln_123
        title: Cross-account invoice access
        description: >-
          An authenticated account can retrieve another account’s invoice by
          changing its ID.
        severity: high
        target: api.example.com
        runId: run_123
        remediation: >-
          Check that the authenticated account owns the invoice before returning
          it.
        status: open
        assignee: null
        riskAcceptance: null
        createdAt: '2026-09-13T10:00:00.000Z'
        updatedAt: '2026-09-13T10:00:00.000Z'
    RiskAcceptance:
      type: object
      properties:
        note:
          type: string
          description: Reason for accepting the risk.
          minLength: 1
        expiresAt:
          type: string
          format: date-time
          description: Time when acceptance expires. Must be in the future when submitted.
      required:
        - note
        - expiresAt
      additionalProperties: false
    Error:
      type: object
      properties:
        error:
          type: object
          properties:
            code:
              type: string
              description: Stable error code.
            message:
              type: string
              description: Description of the problem.
          required:
            - code
            - message
          additionalProperties: false
      required:
        - error
      additionalProperties: false
      example:
        error:
          code: invalid_request
          message: The target value is required.
  responses:
    Error400:
      description: Invalid request
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: invalid_request
              message: Check the request fields and values.
    Error401:
      description: Authentication required
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: unauthorized
              message: Supply a valid API key.
    Error403:
      description: Permission denied
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: forbidden
              message: The API key does not permit this operation or requested scope.
    Error404:
      description: Resource not found
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: not_found
              message: The resource does not exist in this organization.
    Error409:
      description: Conflict
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: conflict
              message: The resource’s current state does not allow this operation.
    Error429:
      description: Too many requests
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: rate_limited
              message: Retry after the interval in Retry-After.
      headers:
        Retry-After:
          description: Seconds to wait before retrying.
          schema:
            type: integer
            minimum: 1
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: x-api-key
      description: >-
        API key from your organization. Supply the value directly, without a
        Bearer prefix.

````