Agentic benchmark
ExploitGym leaderboard
Every model the catalog carries a published ExploitGym value for, ranked by that value.
A controlled benchmark for evaluating whether AI agents can extend vulnerability-triggering inputs into working exploits.
ExploitGym ranking
10 models with a published ExploitGym value, ordered by that value, highest first. Models the source has not scored on this benchmark are not listed — they are unmeasured, not last.
| Rank | Model | Provider | Working exploit generation |
|---|---|---|---|
| 1 | OpenAI | 42.4 | |
| 2 | OpenAI | 33.7 | |
| 3 | OpenAI | 23.2 | |
| 4 | Anthropic | 17.5 | |
| 5 | DeepSeek | 15.3 | |
| 6 | Z.AI | 15.0 | |
| 7 | OpenAI | 13.4 | |
| 8 | OpenAI | 12.4 | |
| 9 | OpenAI | 6.0 | |
| 10 | Meta | 0.8 |
Evidence key: Observed
Rows are ordered by the value ExploitGym: Can AI Agents Turn Security Vulnerabilities into Real Attacks? published, highest first. The source does not state whether a higher value is the better result, so this page does not either: for a benchmark that measures a rate of failure, read the table from the bottom.