macOS
brew install flawzlocal Homebrew formula metadata
sudo port install flawzMacPorts ports tree · security/flawz/Portfile · source: api.github.com
brew / rank 7457
Terminal UI for browsing security vulnerabilities (CVEs). Version 0.4.1 via Homebrew; verified 2026-06-14. Also installable with nix: nix profile install nixpkgs#flawz.
install
brew install flawzlocal Homebrew formula metadata
sudo port install flawzMacPorts ports tree · security/flawz/Portfile · source: api.github.com
sudo apk add flawzAlpine Linux edge package indexes · flawz · source: dl-cdn.alpinelinux.org
nix profile install nixpkgs#flawznixpkgs package indexes · pkgs/by-name/fl/flawz/package.nix · source: api.github.com
sudo pacman -S flawzArch Linux sync databases · flawz · source: geo.mirror.pkgbuild.com
overview
Terminal UI for browsing security vulnerabilities (CVEs)
history
flawz is a Rust terminal user interface for browsing CVE security vulnerability data. It packages NVD-backed vulnerability search into a local CLI/TUI workflow with SQLite storage, theming, offline use, and optional NVD API-key acceleration.
The upstream GitHub repository was created in 2024. The README presents flawz as a terminal UI for browsing security vulnerabilities, using NIST's NVD as the default vulnerability database and offering search, listing, theming, and details views in the terminal.
The release stream began with v0.1.0 in May 2024 and reached v0.4.1 in June 2026, according to the official GitHub releases API.
The official README documents installation through Cargo, Arch Linux official repositories, Alpine Edge, Homebrew, Nixpkgs unstable, NetBSD pkgsrc, binary releases, and source builds. That unusually broad package-manager list for a young Rust TUI reflects quick adoption by distribution packagers interested in CVE tooling.
flawz syncs NVD feeds into a SQLite database, accepts year ranges and recent or modified feeds, and can start directly on a query such as an xz CVE search. Users can pass an NVD API key with `--api-key` or `NVD_API_KEY` for higher NVD rate limits, choose themes, and use offline mode against cached data.
flawz is package-nerd relevant because it combines several current CLI trends in one small package: Rust distribution through crates.io and native package managers, terminal UI ergonomics, local SQLite caching, and security metadata browsing tied to the NVD feed ecosystem.
security posture
narrow executable package without higher-risk signals.
green risk · low confidence · appliance
Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.
executables
| Command | Kind | Exposure | Note |
|---|---|---|---|
flawz | executable | indexed executable | Discovered from the local executable index. |
freshness
These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.
install metadata
| Package key | brew:flawz |
|---|---|
| Version | 0.4.1 |
| Package manager | Homebrew |
| Homepage | https://github.com/orhun/flawz |
| Repository | https://github.com/orhun/flawz |
| Last updated | 2026-06-14T05:08:26Z |
| Pulse | updated |
| Bottle | not recorded |
| Service | none declared |
source database matches
Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.
flawz
nix profile install nixpkgs#flawzflawz 0.4.1-r0
A Terminal UI for browsing CVEs
https://github.com/orhun/flawz
sudo apk add flawzflawz-bash-completion 0.4.1-r0
Bash completions for flawz
https://github.com/orhun/flawz
sudo apk add flawz-bash-completionflawz-doc 0.4.1-r0
A Terminal UI for browsing CVEs (documentation)
https://github.com/orhun/flawz
sudo apk add flawz-docflawz-fish-completion 0.4.1-r0
Fish completions for flawz
https://github.com/orhun/flawz
sudo apk add flawz-fish-completionflawz-zsh-completion 0.4.1-r0
Zsh completions for flawz
https://github.com/orhun/flawz
sudo apk add flawz-zsh-completionflawz 0.4.1-1
A Terminal UI for browsing security vulnerabilities (CVEs)
https://github.com/orhun/flawz
sudo pacman -S flawzflawz
sudo port install flawzsource trail
This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.
View the package source record on GitHub.