Compliance Node Overview
MITRE CAPEC-248 (Command Injection) is a meta-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary looking to execute a command of their choosing, injects new items into an existing command thus modifying interpretation away from what was intended. Commands in this context are often standalone strings that are interpreted by a downstream component and cause specific responses. This type of attack is possible when untrusted values are used to build these command strings. Likelihood of attack: Medium. Typical severity: High. Parent pattern for CAPEC-136 LDAP Injection; CAPEC-183 IMAP/SMTP Command Injection; CAPEC-250 XML Injection; and others. Maps to weaknesses CWE-77.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/248.html
SHA-256 integrity: b2a8b21ee381a6f08c5a6697f9fa0b080d9ffd06a0715cf3a943992d99c4f049
Primary Citations — 8 traced to source
- MITRE CAPEC-248: Command Injection (https://capec.mitre.org/data/definitions/248.html)
- CWE-77: underlying weakness (http://cwe.mitre.org/data/definitions/77.html)
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.