Compliance Node Overview
MITRE CAPEC-175 (Code Inclusion) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary exploits a weakness on the target to force arbitrary code to be retrieved locally or from a remote location and executed. This differs from code injection in that code injection involves the direct inclusion of code while code inclusion involves the addition or replacement of a reference to a code file, which is subsequently loaded by the target and used as part of the code of some application. Likelihood of attack: Medium. Typical severity: Very High. Parent pattern for CAPEC-251 Local Code Inclusion; CAPEC-253 Remote Code Inclusion. Maps to weaknesses CWE-829.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/175.html
SHA-256 integrity: 70ed3ee15032d2ce3e9d87927c781bed895bea783e3efd9043d0d433977bce78
Primary Citations — 7 traced to source
- MITRE CAPEC-175: Code Inclusion (https://capec.mitre.org/data/definitions/175.html)
- CWE-829: underlying weakness (http://cwe.mitre.org/data/definitions/829.html)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.