CoSA: Context-Aware Severity Assessment via Context Analysis with Large Language Models
This study addresses the challenges of missing repository-level evidence and noise interference in automated vulnerability severity assessment by proposing CoSA. The method constructs a Code Property Graph and employs a two-stage pruning strategy combined with an explicit metric-guided LLM retrieval mechanism to obtain precise contextual summaries. A lightweight Transformer is then utilized to predict CVSS metrics. Evaluated on a newly constructed high-quality dataset, experimental results demonstrate that CoSA achieves a 14.4% improvement in accuracy and a 15.3% increase in Macro-F1 score compared to existing baselines. These findings confirm that CoSA significantly outperforms current state-of-the-art methods, effectively enabling accurate repository-level vulnerability severity assessment.