arXiv · 2609.31004
GitHub Engagement Signals for CVE Prioritization: The GitHub Popularity Metric (GPM)
Abstract
Attackers can compromise multiple systems with a single vulnerability, while defenders need to fix all security weaknesses in their systems. This asymmetry puts defenders at a disadvantage. Security vulnerabilities are found at an alarming rate, and patching vulnerabilities is costly and time-consuming; thus, vulnerability prioritization is a must and a time-critical challenge. Many prioritization metrics, such as the CVSS, EPSS, KEV, and SSVC, are currently used, each with different pros and cons, such as openness, degree of automation, time-criticality, coverage, and need for expert input. In this work, we propose the GitHub Popularity Metric (GPM), a fully open, publicly computable prioritization metric based on the popularity of exploits in GitHub repositories. We use GitHub features such as the number of stars, forks, and related unique users to create a metric that indicates the popularity of CVEs across different time frames, both relative to the current time and historically. We compare the proposed metric with various existing vulnerability prioritization metrics and known exploited vulnerabilities and demonstrate that it provides tangible insights for defenders, identifying unique CVEs and inconsistencies in existing methods. The GPM was integrated into the EPSS version 5. \noindent\textbf{Note.} A demonstration based on this work has been accepted to the demo track of the ACM Conference on Computer and Communications Security (CCS) 2026.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Jafar Akhoundali, Kristian Rietveld, Olga Gadyatskaya. 2026-09-25. GitHub Engagement Signals for CVE Prioritization: The GitHub Popularity Metric (GPM). https://arxiv.org/abs/2609.31004
Cite the original work for its findings. Save a collection to share your selection of sources.