# Living CVE **Entity class:** Human-machine vulnerability concept ## Definition A **living CVE** is a person-scale vulnerability-bearing condition in a sociotechnical or cyber-biological system. The term has two connected meanings: 1. A dangerous configuration can arise through the interaction of cognition, capability, access, placement, credentials, environment, and network position. 2. A previously safe person-system can become dangerous when a writable neural interface, its model, or its command pathway is compromised. In the second case, the human being is simultaneously victim, compromised endpoint, and possible vehicle of downstream harm. ## Machine-readable architecture The operational graph links stable but distinct objects: **person or entity identity ↔ implant identity ↔ firmware and software vulnerabilities ↔ model vulnerabilities ↔ access and credential state ↔ neural-state observations ↔ threat state ↔ incidents ↔ remediation and recovery state**. The public CVE namespace remains one input to this graph; the system-level concept is the living endpoint and every path capable of changing its security state. ## Relationships - **foundational concept:** [[wiki/Human CVE|Human CVE]]. - **system:** [[wiki/Cyber-Biological System|Cyber-Biological System]]. - **attack mode:** [[wiki/Brainjacking|Brainjacking]]. - **recovery:** [[wiki/Verified Neural Restoration|Verified Neural Restoration]]. ## Sources / Provenance - U.S. Food and Drug Administration, [Cybersecurity in Medical Devices FAQ](https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity-medical-devices-frequently-asked-questions-faqs), accessed 2026-09-23. - Xinyu Jiang et al., [“Cybersecurity in neural interfaces”](https://pubmed.ncbi.nlm.nih.gov/37883851/), 2023. **As of:** 2026-09-23