{
  "node_id": "mitre-capec-capec-160-exploit-script-based-apis",
  "title": "MITRE CAPEC-160: Exploit Script-Based APIs (Standard Attack Pattern - Medium Severity)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-25",
  "bluf": "MITRE CAPEC-160 (Exploit Script-Based APIs) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Some APIs support scripting instructions as arguments. Methods that take scripted instructions (or references to scripted instructions) can be very flexible and powerful. However, if an attacker can specify the script that serves as input to these methods they can gain access to a great deal of functionality. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-346.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_attack"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-sp-800-53-r5",
    "iso-27001-2022",
    "cis-controls-v8",
    "owasp-asvs-l2"
  ],
  "primary_citations_count": 7
}