Overview - Student Internship Position - AI-assisted Coordinated Vulnerability Disclosure
GCVE.eu provides an open framework for allocating and publishing vulnerability identifiers, while Vulnerability-Lookup collects, correlates, and enriches vulnerability information from multiple sources. This internship aims to connect these projects in order to improve AI-assisted Coordinated Vulnerability Disclosure (CVD) processes without removing the essential review and decision-making performed by vulnerability coordinators.
The precise scope will be selected with the student according to the projects' current needs and the student’s interests and experience. The work may focus on one substantial improvement or combine several related contributions.
Possible tasks include:
- Mapping and documenting the CVD workflow, from the initial report and triage to coordination, identifier allocation, publication, and later updates.
- Integrating GCVE allocation and publication workflows with Vulnerability-Lookup’s CVD features and APIs.
- Developing AI-assisted tools to extract structured information from reports, patches, advisories, and supporting evidence.
- Suggesting vulnerability descriptions, affected products and versions, references, weaknesses, severity information, and other advisory metadata for human review.
- Detecting duplicate or related reports by correlating submissions with records and data sources available in Vulnerability-Lookup.
- Designing review, provenance, confidence, and audit mechanisms so that AI-generated suggestions remain transparent and traceable.
- Evaluating models and prompts with representative CVD cases, measuring quality and documenting failure modes such as unsupported claims, sensitive-data disclosure, and prompt injection.
- Improving interoperability and export using relevant open vulnerability formats and GCVE best current practices.
- Extending automated tests, continuous integration, technical documentation, and deployment guidance for the resulting components.
The internship will begin with a review of GCVE.eu, Vulnerability-Lookup, and existing CVD practices. The student will then define the scope with the maintainers, implement a prototype, and evaluate it using realistic workflows and suitable test data. The work should result in tested, documented, and reusable free software contributions. AI-generated output must be treated as a proposal: publication and other consequential actions must remain under human control.
Qualification
- Must have a valid work permit in Luxembourg.
- Must be eligible for a student internship in the field of information security and/or computer science.
- Must have a high level of ethics due to the sensitive nature of vulnerability reports.
- Must be fluent in English and comfortable working with Unix and git.
- Good knowledge of Python, web APIs, structured data, testing, and software development.
- Knowledge of vulnerability management, CVD, natural-language processing, or large language models is a plus.
- An interest in open standards, responsible vulnerability disclosure, and open-source development.
- Must have a strong willingness to learn new techniques and contribute in collaboration with the projects’ maintainers.
How to apply
The application package must include the following in ASCII text format (language: English):
- A resume.
- A motivation letter explaining why you are interested in the internship and which aspect of AI-assisted CVD you would like to explore.
The package is to be sent to info(@)circl.lu indicating reference internship-vulnerability-01.
Application deadline
Applications are accepted on an ongoing basis while the position is listed as open.
Classification of this document
TLP:CLEAR information may be distributed without restriction, subject to copyright controls.