A preprint reports an evidence-using LLM system led CVSS vulnerability-rating tests, but a small user study and label limits temper the result.