NIST to Open-Source Its NVD AI Enrichment Workflow
The GitHub release marks a quiet admission that NIST can't enrich every CVE alone, and the tooling belongs in the ecosystem's hands.
TL;DR
NIST detailed its V-etalon agentic AI workflow at a Sept. 17 webinar and said the tool will hit GitHub "very soon" as an open-source project. The AI proposes enrichment data for National Vulnerability Database records using evidence traced to public sources like vendor advisories, with decisions mapped to specific passages. NIST won't auto-publish AI-generated enrichment until statistical models justify it. The bigger move: NIST wants the vulnerability management ecosystem to adopt and extend the tooling, not just consume NVD output. The related RFI on modernizing the NVD closes October 13.
The National Vulnerability Database has been running on an unsustainable model. CVE submissions surged 263% between 2020 and 2025, and Q1 2026 ran nearly a third higher than the prior year. NIST enriched nearly 42,000 CVEs in 2025, 45% more than any prior year, and still fell behind. The April 2026 shift to risk-based prioritization was triage: enrich only CVEs in CISA's KEV catalog and those affecting federal software or designated critical under EO 14028. Everything else got a "Lowest Priority" label and an indefinite wait.
V-etalon is the longer-term answer. Craig Schlenoff, chief of NIST's AI Research division, described it as "evidence-based discovery" through specialized AI agents, deterministic controls, and a QA layer. Harold Booth was explicit: the workflow aids analysts now; automated publishing comes later, once statistical models earn sufficient confidence. NIST's own 2023 research showed automated characterization could cut processing time by up to 47% and publish vulnerabilities 95 hours earlier than manual methods.
The ecosystem play is what separates this from an internal productivity project. Booth said NIST wants feedback and participation from everybody building on NVD data: security tool vendors and the vulnerability management teams that depend on enriched CVEs. It's a recognition that the old model of NIST as centralized enricher for the entire federal ecosystem doesn't scale, and that the enrichment tooling itself should be shared infrastructure. Practitioners should watch for the GitHub repo and track the RFI, open through October 13. What NIST builds and what the community does with it may end up diverging.
Published ·Deep Fathom