ZeroDayBench: leaderboard

Metric: Pass rate (%) averaged over five information levels (zero-day, CWE hint, post-exploit report, one-day, full information); tasks: real high-severity CVEs ported into different open-source repositories; the agent (a bash and edit tool loop, up to 100 turns) must find and patch the vulnerability, and success means the patched code passes the exploit test; traces that ran git clone are excluded; higher is better. Source: arxiv.org. Saturation forecast: Around January 2027. 3 models tracked.

Top models

#ModelScoreOverall rank
1Claude Sonnet 4.556#138
2GPT-5.2 (Medium)48.2#105 (GPT-5.2)
3Grok 4.1 Fast (Reasoning)34#208 (Grok 4.1 Fast)

No result here: #3 Claude Opus 5.5, #5 GPT-6 Astra, #8 Claude Fable 5.1.

Interactive version: theaggregate.ai/benchmark?slug=zerodaybench · How It Works · Data refreshed daily, snapshot 2026-10-11.