GitHub Engagement Signals for CVE Prioritization: The GitHub Popularity Metric (GPM)

📅 2026-09-25
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the resource imbalance in vulnerability remediation caused by the proliferation of software vulnerabilities and the limitations of existing prioritization metrics. To overcome these challenges, this work proposes GPM, a fully open and automatically computable CVE prioritization metric that pioneers the quantification of threat levels through open-source community engagement indicators, such as GitHub stars and forks. By leveraging API data mining and time series modeling, the proposed approach enables multidimensional assessment across both historical and real-time contexts. The contributions of this research include the effective identification of uniquely high-risk vulnerabilities and the correction of biases inherent in current metrics. Notably, GPM has been integrated into EPSS v5, and this work has been accepted as a demonstration paper at ACM CCS 2026.
📝 Abstract
Attackers can compromise multiple systems with a single vulnerability, while defenders need to fix all security weaknesses in their systems. This asymmetry puts defenders at a disadvantage. Security vulnerabilities are found at an alarming rate, and patching vulnerabilities is costly and time-consuming; thus, vulnerability prioritization is a must and a time-critical challenge. Many prioritization metrics, such as the CVSS, EPSS, KEV, and SSVC, are currently used, each with different pros and cons, such as openness, degree of automation, time-criticality, coverage, and need for expert input. In this work, we propose the GitHub Popularity Metric (GPM), a fully open, publicly computable prioritization metric based on the popularity of exploits in GitHub repositories. We use GitHub features such as the number of stars, forks, and related unique users to create a metric that indicates the popularity of CVEs across different time frames, both relative to the current time and historically. We compare the proposed metric with various existing vulnerability prioritization metrics and known exploited vulnerabilities and demonstrate that it provides tangible insights for defenders, identifying unique CVEs and inconsistencies in existing methods. The GPM was integrated into the EPSS version 5. \noindent\textbf{Note.} A demonstration based on this work has been accepted to the demo track of the ACM Conference on Computer and Communications Security (CCS) 2026.
Problem

Research questions and friction points this paper is trying to address.

vulnerability prioritization
CVE
security vulnerabilities
prioritization metrics
Innovation

Methods, ideas, or system contributions that make the work stand out.

GitHub Popularity Metric
Vulnerability Prioritization
CVE
Exploit Popularity
EPSS
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
J
Jafar Akhoundali
Leiden University, Netherlands
K
Kristian Rietveld
Leiden University, Netherlands
Olga Gadyatskaya
Olga Gadyatskaya
Associate professor at LIACS, Leiden University
Software securitymobile securityrisk assessment