Compliance Node Overview
MITRE CAPEC-48 (Passing Local Filenames to Functions That Expect a URL) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. This attack relies on client side code to access local files and resources instead of URLs. When the client browser is expecting a URL string, but instead receives a request for a local file, that execution is likely to occur in the browser process space with the browser's authority to local files. The attacker can send the results of this request to the local files out to a site that they control. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-241, CWE-706.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/48.html
SHA-256 integrity: 8b3cd1251f5361a1877aa9d475bff23c9523804ce080f215716ab1043cda2baa
Primary Citations — 8 traced to source
- MITRE CAPEC-48: Passing Local Filenames to Functions That Expect a URL (https://capec.mitre.org/data/definitions/48.html)
- CWE-241: underlying weakness (http://cwe.mitre.org/data/definitions/241.html)
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.