RealVuln: leaderboard
Metric: Strict F3 score (recall weighted nine times over precision) of vulnerability findings against 796 hand-labeled entries (676 vulnerabilities, 120 false-positive traps) in 26 intentionally vulnerable Python repositories, agentic scanning with file, search and shell tools; higher is better. Source: arxiv.org. Saturation forecast: Around April 2027. 10 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | Claude Sonnet 4.6 | 51.7 |
| 2 | Gemini 3.1 Pro (Preview) | 51 |
| 3 | Claude Opus 4.6 | 47.7 |
| 4 | Kimi K2.5 | 46.6 |
| 5 | GLM-5 | 45.8 |
| 6 | MiniMax-M2.7 | 39 |
| 7 | Qwen 3.5 397B A17B | 38.1 |
| 8 | Claude Haiku 4.5 | 37.2 |
| 9 | Grok 4.20 (Reasoning) | 28.4 |
| 10 | Grok 3 | 21.3 |
Interactive version: theaggregate.ai/benchmark?slug=realvuln · How It Works · Data refreshed daily, snapshot 2026-10-07.