Severity rubric (lab impact)
CVSS scores the bug. This rubric scores what it means for a person with one box or a handful. Every card gets exactly one level.
| Level | Label | Meaning for you |
|---|---|---|
| 🔴 | act-tonight | Patch, firewall, or shut it off before bed. |
| 🟠| this-week | Fix at your next maintenance window. Don't let it slide past Sunday. |
| 🟡 | watch | Nothing to do yet. Know it exists; re-check if the situation changes. |
| ⚪ | ignore | Real, but not your problem at lab scale. Listed so you stop worrying. |
How to pick the level
Answer five questions. Each "yes" pushes the level up.
-
Reachable? Is the affected thing commonly exposed to the internet or a tunnel in lab setups (default port-forward, Cloudflare Tunnel, Tailscale Funnel, reverse proxy)?
-
Exploited? Is it in CISA KEV, seen in the wild, or does a public working PoC exist?
- Common? Is the software in the typical lab stack (see
TAGS.md)? -
Blast radius? Does exploitation give a shell, the Docker socket, the hypervisor, secrets, or the LAN? (Leaking a dashboard is less than owning the host.)
-
No friction? Is it exploitable unauthenticated, or with default config/credentials?
| "Yes" count | Default level |
|---|---|
| 4–5 | act-tonight |
| 3 | this-week |
| 1–2 | watch |
| 0 | ignore |
Overrides
-
Always act-tonight: unauthenticated RCE that is being exploited against something you expose. Mass scanning of a homelab port (2375, 11434, 9090, 3000) with a live campaign counts.
-
Cap at watch: requires local access and an already-compromised account, or only affects an enterprise-only feature/edition.
-
Downgrade one level when the fix is on by default for anyone who auto-updates (e.g. Watchtower, unattended-upgrades) and the patch shipped more than 14 days ago.
-
AI stack note: an unauthenticated inference API (Ollama, vLLM, LiteLLM) counts as "blast radius: yes" — it burns your GPU, leaks prompts/keys, and often sits next to tool-calling agents with filesystem or shell access.
Recording it
Put the level in card frontmatter as severity: and the five answers as rubric: so readers
(and future triage) can see why:
severity: act-tonight
rubric: { reachable: true, exploited: true, common: true, blast: true, no_friction: true }