findings
Get finding information by ID
GET
/
findings
/
{id}
Get finding information by ID
curl --request GET \
--url https://app.pentest-tools.com/api/v2/findings/{id} \
--header 'Authorization: Bearer <token>'import requests
url = "https://app.pentest-tools.com/api/v2/findings/{id}"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://app.pentest-tools.com/api/v2/findings/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.pentest-tools.com/api/v2/findings/{id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://app.pentest-tools.com/api/v2/findings/{id}"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://app.pentest-tools.com/api/v2/findings/{id}")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.pentest-tools.com/api/v2/findings/{id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"data": {
"id": 420233,
"name": "Vulnerabilities found for Apache Httpd 2.4.10",
"test_description": "Checking for SQL Injection...",
"test_finished": true,
"confirmed": true,
"epss_score": 123,
"epss_percentile": 123,
"in_cisa_catalog": true,
"cve": [
"CVE-2017-3167",
"CVE-2019-0217"
],
"cvss": 123,
"cvssv3": 123,
"vuln_description": "Vulnerabilities found for Apache Httpd 2.4.25 (port 80/tcp)",
"vuln_evidence": {
"data": {
"headers": [
"<string>"
],
"rows": [
[
"<string>"
]
]
}
},
"risk_description": "<string>",
"recommendation": "<string>",
"references": [
"<string>"
],
"verified": true,
"vuln_id": "NETSCAN-SNIPER-CVE-2021-42013-RCE",
"owasp": {
"owasp_2017": "<string>",
"owasp_2021": "<string>",
"owasp_2025": "<string>"
},
"cwe": "<string>",
"port": 32767,
"group_id": 9876,
"target_id": 12345,
"task_id": 54321,
"screenshots": 1
}
}{
"status": 401,
"message": "No API key specified"
}{
"status": 401,
"message": "No API key specified"
}{
"status": 401,
"message": "No API key specified"
}{
"status": 401,
"message": "No API key specified"
}Authorizations
Use the "API key" from the profile page as the token
Path Parameters
id of finding to get
Response
OK
Show child attributes
Show child attributes
Was this page helpful?
Previous
Update finding statusUpdates the status of a finding and all duplicate findings in the same group.
If the finding already has the requested status and no `status.reason` is provided, the request is a no-op.
If a `status.reason` is provided alongside the same status, the note is recorded in the modification history without changing the status.
Next
⌘I
Get finding information by ID
curl --request GET \
--url https://app.pentest-tools.com/api/v2/findings/{id} \
--header 'Authorization: Bearer <token>'import requests
url = "https://app.pentest-tools.com/api/v2/findings/{id}"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://app.pentest-tools.com/api/v2/findings/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.pentest-tools.com/api/v2/findings/{id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://app.pentest-tools.com/api/v2/findings/{id}"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://app.pentest-tools.com/api/v2/findings/{id}")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.pentest-tools.com/api/v2/findings/{id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"data": {
"id": 420233,
"name": "Vulnerabilities found for Apache Httpd 2.4.10",
"test_description": "Checking for SQL Injection...",
"test_finished": true,
"confirmed": true,
"epss_score": 123,
"epss_percentile": 123,
"in_cisa_catalog": true,
"cve": [
"CVE-2017-3167",
"CVE-2019-0217"
],
"cvss": 123,
"cvssv3": 123,
"vuln_description": "Vulnerabilities found for Apache Httpd 2.4.25 (port 80/tcp)",
"vuln_evidence": {
"data": {
"headers": [
"<string>"
],
"rows": [
[
"<string>"
]
]
}
},
"risk_description": "<string>",
"recommendation": "<string>",
"references": [
"<string>"
],
"verified": true,
"vuln_id": "NETSCAN-SNIPER-CVE-2021-42013-RCE",
"owasp": {
"owasp_2017": "<string>",
"owasp_2021": "<string>",
"owasp_2025": "<string>"
},
"cwe": "<string>",
"port": 32767,
"group_id": 9876,
"target_id": 12345,
"task_id": 54321,
"screenshots": 1
}
}{
"status": 401,
"message": "No API key specified"
}{
"status": 401,
"message": "No API key specified"
}{
"status": 401,
"message": "No API key specified"
}{
"status": 401,
"message": "No API key specified"
}