Compliance Node Overview
MITRE CAPEC-676 (NoSQL Injection) is a standard-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. An adversary targets software that constructs NoSQL statements based on user input or with parameters vulnerable to operator replacement in order to achieve a variety of technical impacts such as escalating privileges, bypassing authentication, and/or executing code. Likelihood of attack: High. Typical severity: High. Maps to weaknesses CWE-943, CWE-1286.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/676.html
SHA-256 integrity: 144de2bce7ea6033457393fc9edb5ea3599004b1bd3ded99f9dee9838d14fe31
Primary Citations — 9 traced to source
- MITRE CAPEC-676: NoSQL Injection (https://capec.mitre.org/data/definitions/676.html)
- CWE-943: underlying weakness (http://cwe.mitre.org/data/definitions/943.html)
+ 7 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.