OSP.0.1.0 · PurpleLotus

Introducing OspreySecurity beyond CVEs

The CLI that builds an SBOM, cross-checks every component against CISA KEV, and tells you which dependencies are actively exploited in the wild — not merely have a CVE.

∵Because 99% of vulnerabilities are noise∵
KEV 1.1live

v2026.09.30 · 1,730 in catalog · 2026-09-30

CVE-2026-76504 Cisco Catalyst SD-WAN Manager · CVE-2026-86950 Apple Multiple Products · CVE-2026-88772 Citrix NetScaler · CVE-2026-88771 Citrix NetScaler · CVE-2026-67279 MikroTik RouterOS · CVE-2026-65660 Microsoft SharePoint · CVE-2026-87902 WordPress Core · CVE-2026-5430 WSO2 Multiple Products · CVE-2026-76504 Cisco Catalyst SD-WAN Manager · CVE-2026-86950 Apple Multiple Products · CVE-2026-88772 Citrix NetScaler · CVE-2026-88771 Citrix NetScaler · CVE-2026-67279 MikroTik RouterOS · CVE-2026-65660 Microsoft SharePoint · CVE-2026-87902 WordPress Core · CVE-2026-5430 WSO2 Multiple Products

PULSE 1.1CISA

1,730

known exploited in the wild

Added (7d)

9

Due (14d)

2

Ransomware

361

polling CISA…

NEWEST 1.1DATE ADDED
  • CVE-2026-76504Cisco / Catalyst SD-WAN Manager2026-09-30
  • CVE-2026-86950Apple / Multiple Products2026-09-29
  • CVE-2026-88772Citrix / NetScaler2026-09-27
  • CVE-2026-88771Citrix / NetScaler2026-09-27
  • CVE-2026-67279MikroTik / RouterOS2026-09-25
  • CVE-2026-65660Microsoft / SharePoint2026-09-25
  • CVE-2026-87902WordPress / Core2026-09-25
  • CVE-2026-5430WSO2 / Multiple Products2026-09-24
WATCH 1.1
  • CVE-2026-86950Apple / Multiple Products2026-10-02
  • CVE-2026-76504Cisco / Catalyst SD-WAN Manager2026-10-03
CATALOG 1.11,730
  • Showing 80 of 1,730. Narrow the search.
Active known-exploited vulnerabilities · CISA KEVcisa.gov catalog

We asked a narrower question

not every CVE

Most vulnerability tooling stops at “this package has a CVE.” That produces a lot of tickets and very little prioritization: a scanner that flags every CVE in your dependency tree, regardless of whether it is actually being exploited, trains teams to ignore the output.

Osprey narrows the question to the one that actually matters for triage — is this specific component, at this specific version, known to be exploited right now?

a new signal

Known exploited, not merely listed.

CISA’s KEV catalog tracks vulnerabilities known to have been exploited in the wild. Osprey correlates that with the dependencies found in a project.

version-aware

The installed version, not the package name.

OSV decides whether your installed version is affected, not_affected, or unknown. Unknown is never treated as affected.

more like triage

A security signal your process can act on.

Confidence tiers, remediation paths, SARIF, and --fail-on-high. Software can branch on the result instead of drowning in a CVE dump.

Triage, not theater

99% of findings are noise.
We find the 1% that matters.

Based on a typical npm lockfile run against CISA KEV — not a count of every CVE in NVD.

Osprey

2

known-exploited, version-affected packages

Audit completed in 1.42s · exit 1 with --fail-on-high

Typical CVE scanner

1,847

CVEs flagged, regardless of exploitation

Hours of triage · most tickets never move

Built for the gate

cra returns a graded signal, so your software can act when confidence is high and escalate when it is not.

KEV detection

Cross-checks every SBOM component against CISA’s Known Exploited Vulnerabilities catalog — the 1% that hackers are using right now.

Confidence tiers

high is a PURL-backed exact match. low is a name/vendor coincidence. Never panic over a string collision.

Version intelligence

OSV decides whether your installed version is actually affected — not whether the package ever had a CVE.

Remote auditing

Point cra at owner/repo. No clone. Private repos take a GitHub token.

SBOM signing

Ed25519 signatures in a DSSE envelope, with tamper detection, so the inventory is verifiable.

CI-ready

JSON results, GitHub Actions job summaries, inline annotations, SARIF, and --fail-on-high for the gate.

Interactive · cra 0.1.0

The CLI, in the page.

Same commands as the real binary. Audit the demo app, a clean tree, or facebook/react. Flags: --verbose, --summary, --fail-on-high. This is a faithful in-browser tty of Purplelotusec/Osprey.

Enter · ↑ history · Tab complete · Ctrl+C

cra — osprey 0.1.0
osprey 0.1.0 — cra demo tty
Type a command or click a preset. Try `cra --help`.
 
~/acme-web $

How it works

One command, the whole pipeline.

cra --path /path/to/your/project
cra --url owner/repo
cra --path . --fail-on-high --output results.json
  1. 01

    Software / Repository

  2. 02

    Dependencies

  3. 03

    SBOM

  4. 04

    Vulnerability analysis

  5. 05

    CISA KEV match

  6. 06

    Security signal

  7. 07

    Investigate & respond

versionStatusMeaning
affectedOSV evidence covers the installed version
not_affectedAvailable evidence excludes the installed version
unknownEvidence couldn't be established — never treated as affected

We give a FAQ

Questions, one at a time.

Osprey is an open-source CLI for software supply chain visibility. cra is the command. It builds a Software Bill of Materials from your project, cross-checks every component against the CISA KEV catalog, and tells you which dependencies are actively exploited in the wild — not merely “have a CVE.”

Osprey notes

Get started

Ship with Osprey.

git clone https://github.com/Purplelotusec/Osprey
cd Osprey
npm install
npm link
cra --path .