Compliance Node Overview
MITRE CAPEC-242 (Code Injection) is a meta-level attack pattern in which an adversary exploits a weakness in input validation on the target to inject new code into that which is currently executing. Likelihood of attack: High. Typical severity: High. CAPEC-242 is the parent pattern for CAPEC-63 Cross-Site Scripting, CAPEC-23 File Content Injection, CAPEC-19 Embedding Scripts within Scripts. Maps to CWE-94 (Improper Control of Generation of Code). Compliance: OWASP ASVS V5.3, OWASP Top 10 A03:2021, PCI DSS v4.0 Req 6.2, NIST SP 800-53 SI-10, ISO/IEC 27001 (secure coding).
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/242.html
SHA-256 integrity: 4817f731eb0a3e3daf7490cf8ad11e8fe029108318f5ea7d2441c601007cd26c
Primary Citations — 8 traced to source
- MITRE CAPEC-242: Code Injection (https://capec.mitre.org/data/definitions/242.html)
- CWE-94: Improper Control of Generation of Code (Code Injection)
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.