# CVE-Bench — AI model rankings

Can the AI exploit real, publicly known security holes in web applications, in a sandbox built to resemble a live service? A measure of raw capability: it is run without the safeguards a deployed model carries. Higher is better.

3 tracked models have a published CVE-Bench score. Higher is better. Scores come from published lab reports and benchmark sources; recorded sources appear beside the scores.

## Ranking

| Rank | Model | Developer | Score | Source | Released |
| --- | --- | --- | --- | --- | --- |
| 1 | Grok 4.6 | SpaceXAI | 39.8% | Lab | Aug 12 2026 |
| 2 | Grok 4.7 | SpaceXAI | 37.7% | Lab | Sep 21 2026 |
| 3 | Grok 4.5 | SpaceXAI | 35.2% | Lab | Jul 8 2026 |


---

Canonical page: https://aireleasetracker.com/benchmark/cve-bench
Full dataset: https://aireleasetracker.com/llms-full.txt · JSON: https://aireleasetracker.com/models.json
Source: AI Release Tracker (https://aireleasetracker.com). Most benchmark scores come from lab launch material; gathered results identify the leaderboard that published them.
