Update finding status
Updates the status of a finding and all duplicate findings in the same group.
If the finding already has the requested status and no status.reason is provided, the request is a no-op.
If a status.reason is provided alongside the same status, the note is recorded in the modification history without changing the status.
curl --request PATCH \
--url https://app.pentest-tools.com/api/v2/findings/{id} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{}'import requests
url = "https://app.pentest-tools.com/api/v2/findings/{id}"
payload = {}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PATCH',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({})
};
fetch('https://app.pentest-tools.com/api/v2/findings/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.pentest-tools.com/api/v2/findings/{id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PATCH",
CURLOPT_POSTFIELDS => json_encode([
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.pentest-tools.com/api/v2/findings/{id}"
payload := strings.NewReader("{}")
req, _ := http.NewRequest("PATCH", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.patch("https://app.pentest-tools.com/api/v2/findings/{id}")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.pentest-tools.com/api/v2/findings/{id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Patch.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{}"
response = http.request(request)
puts response.read_body{
"data": {
"id": 420233,
"name": "Vulnerabilities found for Apache Httpd 2.4.10",
"test_description": "Checking for SQL Injection...",
"test_finished": true,
"confirmed": true,
"epss_score": 123,
"epss_percentile": 123,
"in_cisa_catalog": true,
"cve": [
"CVE-2017-3167",
"CVE-2019-0217"
],
"cvss": 123,
"cvssv3": 123,
"vuln_description": "Vulnerabilities found for Apache Httpd 2.4.25 (port 80/tcp)",
"vuln_evidence": {
"data": {
"headers": [
"<string>"
],
"rows": [
[
"<string>"
]
]
}
},
"risk_description": "<string>",
"recommendation": "<string>",
"references": [
"<string>"
],
"verified": true,
"vuln_id": "NETSCAN-SNIPER-CVE-2021-42013-RCE",
"owasp": {
"owasp_2017": "<string>",
"owasp_2021": "<string>",
"owasp_2025": "<string>"
},
"cwe": "<string>",
"port": 32767,
"group_id": 9876,
"target_id": 12345,
"task_id": 54321,
"screenshots": 1
}
}{
"status": 401,
"message": "No API key specified"
}{
"status": 401,
"message": "No API key specified"
}{
"status": 401,
"message": "No API key specified"
}{
"status": 401,
"message": "No API key specified"
}{
"status": 401,
"message": "No API key specified"
}Authorizations
Use the "API key" from the profile page as the token
Headers
Set to return=representation to receive the updated finding in the response body instead of 204 No Content.
return=representation Path Parameters
ID of the finding to update
Body
The fields to modify on a finding. At least one modifiable field is required.
Each field is an object with a value and an optional reason.
Show child attributes
Show child attributes
Response
OK — returned only when the Prefer: return=representation request header is set
Show child attributes
Show child attributes
Was this page helpful?
curl --request PATCH \
--url https://app.pentest-tools.com/api/v2/findings/{id} \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{}'import requests
url = "https://app.pentest-tools.com/api/v2/findings/{id}"
payload = {}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PATCH',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({})
};
fetch('https://app.pentest-tools.com/api/v2/findings/{id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.pentest-tools.com/api/v2/findings/{id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PATCH",
CURLOPT_POSTFIELDS => json_encode([
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.pentest-tools.com/api/v2/findings/{id}"
payload := strings.NewReader("{}")
req, _ := http.NewRequest("PATCH", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.patch("https://app.pentest-tools.com/api/v2/findings/{id}")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.pentest-tools.com/api/v2/findings/{id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Patch.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{}"
response = http.request(request)
puts response.read_body{
"data": {
"id": 420233,
"name": "Vulnerabilities found for Apache Httpd 2.4.10",
"test_description": "Checking for SQL Injection...",
"test_finished": true,
"confirmed": true,
"epss_score": 123,
"epss_percentile": 123,
"in_cisa_catalog": true,
"cve": [
"CVE-2017-3167",
"CVE-2019-0217"
],
"cvss": 123,
"cvssv3": 123,
"vuln_description": "Vulnerabilities found for Apache Httpd 2.4.25 (port 80/tcp)",
"vuln_evidence": {
"data": {
"headers": [
"<string>"
],
"rows": [
[
"<string>"
]
]
}
},
"risk_description": "<string>",
"recommendation": "<string>",
"references": [
"<string>"
],
"verified": true,
"vuln_id": "NETSCAN-SNIPER-CVE-2021-42013-RCE",
"owasp": {
"owasp_2017": "<string>",
"owasp_2021": "<string>",
"owasp_2025": "<string>"
},
"cwe": "<string>",
"port": 32767,
"group_id": 9876,
"target_id": 12345,
"task_id": 54321,
"screenshots": 1
}
}{
"status": 401,
"message": "No API key specified"
}{
"status": 401,
"message": "No API key specified"
}{
"status": 401,
"message": "No API key specified"
}{
"status": 401,
"message": "No API key specified"
}{
"status": 401,
"message": "No API key specified"
}