Common Weakness Enumeration (CWE) is essentially a dictionary for security vulnerabilities. Each entry describes a type of weakness in software or hardware, giving it a unique identifier and explaining what makes it problematic.
When security tools report findings, they often reference CWE identifiers. "CWE-89: SQL Injection" tells you exactly what type of issue was found, linking to documentation about how the weakness works and how to prevent it.
Why It Matters
CWE provides a common vocabulary for discussing security issues. Instead of one tool calling a vulnerability "SQL injection" and another calling it "database query manipulation," they can both reference CWE-89 and everyone knows they're talking about the same thing.
This standardization makes it easier to compare findings across tools, track vulnerability types over time, and communicate about security issues without ambiguity.
Structure
CWE entries are organized hierarchically. High-level entries describe broad categories (like "improper input validation"), while more specific entries describe particular manifestations (like "SQL injection" or "path traversal"). This structure helps in understanding how different weakness types relate to each other.
Each entry includes a description, potential consequences, examples, and guidance on detection and prevention. The entries are maintained by MITRE with input from the broader security community.
Relationship to AI Coding
When ACSM tools check AI-generated code for security issues, they're often looking for patterns that correspond to specific CWEs. The CWE framework provides a systematic way to categorize what the security tool is checking for and what issues it finds.
Benchmarks like BaxBench associate their test scenarios with specific CWEs, making it clear which types of vulnerabilities a model is prone to generating. Corridor uses CWE identifiers when reporting issues, making it easy to understand exactly what was found.