Skip to main content

Vulnerability reports from Agentic Pentest

Learn more about the key information contained on Agentic Pentest vulnerability reports

With the YesWeHack Agentic Pentest solution, launch on-demand penetration testing and receive final results the same day.

The solution covers a broad range of vulnerabilities (eg., IDOR, Broken Access Control, Remote Code Execution (RCE), etc.). Be notified of each new finding, and access an actionable report, including a detailed proof of concept and remediation guidance, through the platform.


Vulnerability Report’s overview

ℹ️ All YesWeHack’s Vulnerability Reports are consolidated in the Vulnerability Center, whether they come from Agentic pentest or any other YesWeHack solution, such as Bug Bounty or Exposure Management.

A vulnerability report contains all the important information you need to properly assess the bug and start your remediation process.

Starting with the report header, which includes:

  • The Report ID, taking the following format: #YWH-PGMXXXXX

  • The Report status - which is “New” when the report appears in the Vulnerability Center

  • The Title, which is a summary of metadata and bug impact and can be edited

  • The program name

  • The report submitter (i.e. YWH_AGP for agentic pentest reports)

  • The number of comments

The “Quick Actions” bar lets you navigate quickly on the different segments of the reports:

  • Change status

  • Members management

  • Export

The right-end side panel helps you evaluate the risks:

  • Priority based on CVSS, Exploitability score, and asset value (as defined by organisations).

  • CVSS score.

  • Asset value as indicated in the program’s scopes.

It also features key report’s data:

  • Report metadata, which are also used to generate the report’s title

  • Tag management system

  • Tracking status


Bug description and report processing

The report starts with a bug description that includes:

  • A summary of the vulnerability that enables you to quickly understand its nature and impact.

  • A detailed proof of concept with step-by-step instructions, enabling its complete reproduction.

ℹ️ This section includes the requests sent, the responses received, screenshots of key steps, and the exploitation logic followed.

  • The potential impact if the vulnerability is exploited.

  • And remediation guidance.

⚠️ No vulnerability is reported until its exploitation has been successfully completed. Each reported vulnerability includes a proof of exploitability, validated according to the same standards applied by our Bug Bounty triage team.

The bug report is followed by the comment thread where you can track the evolution of the report over time (e.g., comments, report status).

  • Messages visible to everyone will be tagged:

  • As well as messages only visible to your team:

ℹ️ For more information about the reports' workflow, check out our dedicated article.


Vulnerability report management

At the end of a vulnerability report, find a “quick actions” section to easily manage your report.

ℹ️ To know how to manage an Agentic Pentest vulnerability report (e.g., change the status, send comment to your team), click here.

Did this answer your question?