Where the CVSS-based method is chosen, the rating should come from the exploitability metrics in the base metric group, namely attack complexity, attack vector, user interaction and privileges required (Annex G.3).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.