ZeroDayBench - Zero-Day: leaderboard
Metric: Pass rate (%) when the agent is told only to find and patch a critical vulnerability; tasks: real high-severity CVEs ported into different open-source repositories; the agent (a bash and edit tool loop, up to 100 turns) must find and patch the vulnerability, and success means the patched code passes the exploit test; traces that ran git clone are excluded; higher is better. Source: arxiv.org. Saturation forecast: Around 2029. 3 models tracked.
Top models
| # | Model | Score | Overall rank |
|---|---|---|---|
| 1 | GPT-5.2 (Medium) | 14.4 | #105 (GPT-5.2) |
| 2 | Claude Sonnet 4.5 | 12.8 | #138 |
| 3 | Grok 4.1 Fast (Reasoning) | 12.1 | #208 (Grok 4.1 Fast) |
No result here: #3 Claude Opus 5.5, #5 GPT-6 Astra, #8 Claude Fable 5.1.
Interactive version: theaggregate.ai/benchmark?slug=zerodaybench-zero-day · How It Works · Data refreshed daily, snapshot 2026-10-11.