Compliance Node Overview
MITRE CAPEC-160 (Exploit Script-Based APIs) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Some APIs support scripting instructions as arguments. Methods that take scripted instructions (or references to scripted instructions) can be very flexible and powerful. However, if an attacker can specify the script that serves as input to these methods they can gain access to a great deal of functionality. Likelihood of attack: Unknown. Typical severity: Medium. Maps to weaknesses CWE-346.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/160.html
SHA-256 integrity: 9caea1532d3ffd6a28f82f79ba9265522bff90e1beb6ce15f982529bb10246b6
Primary Citations — 7 traced to source
- MITRE CAPEC-160: Exploit Script-Based APIs (https://capec.mitre.org/data/definitions/160.html)
- CWE-346: underlying weakness (http://cwe.mitre.org/data/definitions/346.html)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.