> For the complete documentation index, see [llms.txt](https://support.attackforge.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://support.attackforge.com/app/modules/ai-mcp-and-skills/update-vulnerability-status.md).

# Update Vulnerability Status

#### Description <a href="#description" id="description"></a>

Updates the status of an AttackForge vulnerability (also called a finding or issue) inside an existing project. This is a **write** operation.

Use this tool - **not** `patch_vulnerability` - whenever you want to reopen, close, or request a retest of a vulnerability. `patch_vulnerability` cannot make these transitions.

The shape of `args` is declared inline (see Building args for Write Tools), so no preparatory call is needed. The accepted shape depends on the status being set:

* `Open` and `Closed` both **require** a `reason` explaining the change.
* `Retest` requests a retest to confirm remediation and must be sent **without** a `reason`.

Preconditions: the caller needs Edit access to the target vulnerability. On success the updated vulnerability id is returned.

#### How To Enable <a href="#how-to-enable" id="how-to-enable"></a>

1. Go to `Users`
2. Select the user you would like to provide access to this tool
3. Click on `Access > MCP`
4. Click on `Add Tools`
5. Select the tool `update_vulnerability_status` and click `Add`

#### Example Prompts <a href="#example-prompts" id="example-prompts"></a>

* *Close vulnerability X - the issue has been fixed.*
* *Close this finding, the risk has been formally accepted.*
* *Reopen vulnerability X, it has not been fixed.*
* *Submit vulnerability X for retest.*
* *Request a retest on all the critical findings I fixed in project Y.*

#### Parameters <a href="#parameters" id="parameters"></a>

| Parameter | Type   | Required | Description                                                                                 |
| --------- | ------ | -------- | ------------------------------------------------------------------------------------------- |
| `args`    | object | Yes      | The status-update payload. Its accepted keys depend on `status` - see the two shapes below. |

**`args` for `Open` / `Closed`:**

| Key                | Type   | Required | Description                                                                                                                                                                                                                                   |
| ------------------ | ------ | -------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `project_id`       | string | Yes      | Id (24-hex) of the project the vulnerability belongs to. Source: `find_projects`.                                                                                                                                                             |
| `vulnerability_id` | string | Yes      | Id (24-hex) of the vulnerability. Source: `find_vulnerabilities`.                                                                                                                                                                             |
| `status`           | string | Yes      | `'Open'` when the vulnerability is still present and unresolved, or `'Closed'` when it no longer needs to be tracked.                                                                                                                         |
| `reason`           | string | Yes      | Why the status is being changed. For `Open`, e.g. `"Issue has not been fixed"`. For `Closed`, e.g. `"Issue has been fixed"` or `"Risk accepted"`. Prefer the suggested wording when it matches; otherwise supply a specific free-text reason. |

**`args` for `Retest`:**

| Key                | Type   | Required | Description                                                                                  |
| ------------------ | ------ | -------- | -------------------------------------------------------------------------------------------- |
| `project_id`       | string | Yes      | Id (24-hex) of the project the vulnerability belongs to. Source: `find_projects`.            |
| `vulnerability_id` | string | Yes      | Id (24-hex) of the vulnerability being submitted for retest. Source: `find_vulnerabilities`. |
| `status`           | string | Yes      | Must be `'Retest'`.                                                                          |

> `reason` must **not** be supplied when `status` is `'Retest'`; the call is rejected if it is.

#### Example Response

```json
{
  "id": "656168055d7035a12ade4cb3"
}
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://support.attackforge.com/app/modules/ai-mcp-and-skills/update-vulnerability-status.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
