---
title: RuleBodyVulnerabilityInput input | Wartiva GraphQL API
description: Input variant of RuleBodyVulnerability. A rule with this body must apply to APPLICATION_INSTALL, ENDPOINT, or SERVICE, the object types that carry CPEs.
url: https://wartiva.com/api-docs/types/rule-body-vulnerability-input.html
updated: 2026-10-07
---

Policies and findings · GraphQL input

# `RuleBodyVulnerabilityInput` input

Input variant of [RuleBodyVulnerability](https://wartiva.com/api-docs/types/rule-body-vulnerability.html). A rule with this body must apply to APPLICATION_INSTALL, ENDPOINT, or SERVICE, the object types that carry CPEs.

## Fields

| Input Field | Description |
|---|---|
| `granularity` - [`RuleVulnerabilityGranularity!`](https://wartiva.com/api-docs/types/rule-vulnerability-granularity.html) | Whether the rule raises a record for each matched CVE or one per object. Default = `PER_CVE` |
| `minimumSeverity` - [`Severity`](https://wartiva.com/api-docs/types/severity.html) | When set, only CVEs whose severity is at or above this severity are raised. A CVE's severity is its CVSS rating, raised when its EPSS score shows it's likely to be exploited soon, so a CVE with neither is not raised. |
| `knownExploitedOnly` - [`Boolean!`](https://wartiva.com/api-docs/types/boolean.html) | When true, only CVEs on the CISA Known Exploited Vulnerabilities catalog are raised. Default = `false` |
| `excludedCveIds` - [`[String!]`](https://wartiva.com/api-docs/types/string.html) | CVE ids never raised by this rule, as accepted risk. Each must be a CVE id such as CVE-2024-12345. |

## Used by

- [`RuleBodyInput`](https://wartiva.com/api-docs/types/rule-body-input.html) input: One-of input mirroring the RuleBody union.

## Example

### Example

```json
{
  "granularity": "PER_CVE",
  "minimumSeverity": "INFORMATIONAL",
  "knownExploitedOnly": true,
  "excludedCveIds": ["xyz789"]
}

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
