v1

latestOpenAPI 3.0.1Vanta Terms of Service2026-07-26327517821.8 KB
Audits

List vulnerabilities within the scope of a given audit

List all vulnerabilities based on selected filters.

End of life — this endpoint works for classic audits only; it does not support controlled audit view. It remains available for existing classic audits but will be removed once classic audits are fully phased out, so do not build new integrations on it.

Rate limit: 10 requests / minute.

get/audits/{auditId}/vulnerabilities

Path parameters

auditIdstring required

Query parameters

querystring

Filter vulnerabilities by search query

pageSizeinteger

Controls the maximum number of items returned in one response from the API.

pageCursorstring

A marker or pointer, telling the API where to start fetching items for the subsequent page in a paginated dataset. Note that the requested page will not include the item that corresponds to this cursor but will start from the one immediately after this cursor.

isDeactivatedboolean

Filter vulnerabilities by deactivation status.

externalVulnerabilityIdstring

Filter vulnerabilities based on a specific external ID.

isFixAvailableboolean

Filter vulnerabilities that have an available fix.

packageIdentifierstring

Filter vulnerabilities that are from a specific package.

slaDeadlineAfterDatestring date-time

Filter vulnerabilities with a fix due after a specific timestamp

slaDeadlineBeforeDatestring date-time

Filter vulnerabilities with a fix due before a specific timestamp

severity'CRITICAL' | 'HIGH' | 'LOW' | 'MEDIUM'

ExternalFindingSeverity describes the severity of an external finding (Vulnerability or Security Alert)

Filter vulnerabilities by severity. Possible values: CRITICAL, HIGH, MEDIUM, LOW.

integrationIdstring

Filter vulnerabilities by the vulnerability scanner that detected them.

includeVulnerabilitiesWithoutSlasboolean

Filter vulnerabilities without an SLA due date.

vulnerableAssetIdstring

Filter vulnerabilities by a specific asset ID.

Response

Ok