Skip to content

Templates by weakness class

The catalog sorted by the class of defect a check is looking for, taken from each template’s own @cwe header. A template may name several, and appears under each.

Weakness Checks
CWE-20 cli-baseline-b12-crash-hang
CWE-22 agent-extension-install-path-containment, cli-baseline-b03-path-traversal, cli-baseline-b04-archive-traversal, directory-traversal, triton-model-control-exposed
CWE-77 coding-agent-command-trace-composition
CWE-78 cli-baseline-b02-command-injection, flowise-custommcp-command-endpoint-exposed
CWE-79 xss-detection-c
CWE-88 cli-baseline-b01-argument-injection
CWE-89 ai-assisted-fuzzing-sqli-seed-corpus, sql-injection-basic, sql-injection-detection-c, timing-attack-detection
CWE-93 mcp-client-header-value-encoding
CWE-94 actions-injection-scanner, claude-code-sed-bypass-usage, coding-agent-git-config-exec, flowise-custommcp-js-eval-exposed, jenkins-unauth-rce, jupyter-unauth-rce, pwn-request-scanner, spring4shell-detection, ssti-engine-fingerprint
CWE-113 mcp-client-header-value-encoding, response-integrity-audit
CWE-119 smart-install-exposed
CWE-134 cli-baseline-b14-format-string
CWE-150 cli-baseline-b08-terminal-escape
CWE-200 cadvisor-exposed-javascript, cadvisor-exposed-python, check-metrics-endpoint, ci-variable-exposure, dhcpv6-solicit-response, directory-listing-common-paths, dns-udp-service-probe, dns-zone-transfer, echo-service-exposed, elasticsearch-data-exposure, epmd-node-list-exposed, exposed-ollama-api-version, finger-service-exposed, ghes-version-fingerprint, gitlab-version-fingerprint, graphql-user-enumeration, grpc-reflection-abuse, helm-chart-secrets-leak, http-service-detection, icmp-echo-reachable, ident-exposed, influxdb-health-exposed, k8s-etcd-exposed, kibana-api-status-exposed, mcp-cache-scope-identity-leak, mdns-service-discovery-probe, mysql-exporter-exposed, nbns-name-query-probe, ndmp-service-exposed, node-exporter-exposed-javascript, node-exporter-exposed-python, ntp-udp-service-probe, postgresql-exporter-exposed, prometheus-server-exposed-javascript, rabbitmq-management-exposed, redis-exporter-exposed, redis-exporter-exposed-python, rsync-banner-exposed, sensitive-data-exposure, splunk-web-login-exposed, ssdp-msearch-response, tacacs-service-exposed, tcp-banner-probe, tcp-port-reachability, tftp-service-exposed, whois-service-exposed, wsd-probe-response
CWE-204 password-reset-enum
CWE-214 cli-baseline-b05-argv-secrets
CWE-250 mcp-child-env-inheritance, mcp-excessive-scope-proof, mcp-excessive-tool-permissions
CWE-269 k8s-rbac-misconfiguration, vertical-privesc-admin
CWE-284 ftp-anonymous-access, kubernetes-api-unauthenticated, mcp-excessive-scope-proof, smtp-open-relay
CWE-285 jwt-role-tampering
CWE-287 auth-bypass-flow, kafka-unauthenticated-access, mcp-broken-token-validation, mcp-token-audience-confusion
CWE-295 tls-certificate-deep-analysis
CWE-306 adb-exposed, api-pull-access-check, clickhouse-auth-bypass, cockroachdb-unauthenticated-access, copilot-yolo-autoapprove-enabled, docker-api-unauth, docker-registry-unauthenticated, elasticsearch-data-exposure, elasticsearch-unauthenticated, etcd-running-unauthenticated-port, etcd-unauthenticated, flowise-custommcp-command-endpoint-exposed, flowise-custommcp-js-eval-exposed, invokeai-model-install-exposed, istio-pilot-misconfiguration, jenkins-unauth-rce, jupyter-unauth-rce, k8s-etcd-exposed, kafka-unauthenticated, kubelet-api-exposure, kubernetes-api-unauthenticated, mcp-unauthenticated-access, memcached-unauthenticated-access, mongodb-unauthenticated, mqtt-unauthenticated, nats-unauthenticated-banner, ollama-unauth-api-generate, prometheus-server-exposed-https, prometheus-server-exposed-python, redis-cluster-takeover, redis-unauthenticated-access, redis-unauthenticated-c, redis-unauthenticated-cpp, redis-unauthenticated-go, redis-unauthenticated-java, redis-unauthenticated-javascript, redis-unauthenticated-perl, redis-unauthenticated-php, redis-unauthenticated-python, redis-unauthenticated-ruby, redis-unauthenticated-rust, redis-unauthenticated-shell, rmi-service-enumeration, socks5-no-auth, splunkd-server-info-exposed, torchserve-management-api-exposed, triton-model-control-exposed, vnc-no-auth, zookeeper-unauthenticated-access
CWE-307 rate-limit-auth-bypass
CWE-312 git-history-secret-scan, sensitive-data-exposure
CWE-327 jwt-alg-confusion
CWE-345 mcp-manifest-runtime-divergence, mcp-rug-pull-detection
CWE-346 mcp-client-mrtr-conformance, mcp-client-oauth-issuer-binding
CWE-350 dns-rebinding-attack
CWE-359 graphql-user-enumeration
CWE-362 race-condition-exploit
CWE-366 race-condition-exploit
CWE-367 cli-baseline-b13-toctou-symlink-race, dns-rebinding-attack, race-condition-exploit
CWE-377 cli-baseline-b06-insecure-temp-files
CWE-384 session-fixation-check
CWE-400 http2-rapid-reset
CWE-425 forced-browse-auth-bypass
CWE-426 cli-baseline-b07-path-hijack
CWE-427 coding-agent-workspace-interpreter-shadowing
CWE-441 mcp-oauth-consent-dcr-abuse, mcp-token-audience-confusion
CWE-444 mcp-method-desync, response-integrity-audit
CWE-454 cli-baseline-b09-environment-trust
CWE-494 mcp-manifest-runtime-divergence
CWE-497 check-metrics-endpoint
CWE-502 deserialization-gadget-scan, invokeai-model-install-exposed, log4shell-detection, ml-unsafe-deserialization-usage, pytorch-unsafe-load-usage, torchserve-management-api-exposed
CWE-506 supply-chain-install-hook-behavior
CWE-522 mcp-client-oauth-issuer-binding, mcp-credential-exposure, service-account-token-abuse, supply-chain-install-credential-access
CWE-524 mcp-cache-scope-identity-leak
CWE-538 grpc-reflection-abuse
CWE-565 mcp-handle-binding-integrity
CWE-601 mcp-oauth-consent-dcr-abuse
CWE-613 auth-token-logout-reuse
CWE-639 idor-bola-horizontal, mcp-handle-binding-integrity
CWE-668 coding-agent-sandbox-trust-handoff
CWE-693 agent-skill-hidden-instruction-trust, coding-agent-hook-gate-integrity, coding-agent-sandbox-perimeter-enforcement
CWE-732 cli-baseline-b10-config-credential-handling, coding-agent-config-allowlist-trust, coding-agent-project-local-config-trust, coding-agent-shared-config-trust
CWE-770 http2-rapid-reset
CWE-787 cli-baseline-b11-memory-safety
CWE-798 ci-variable-exposure, couchdb-default-credentials, helm-chart-secrets-leak, mysql-default-credentials, postgresql-default-credentials, rabbitmq-default-credentials, snmp-default-community
CWE-807 mcp-client-untrusted-annotation-approval
CWE-829 agent-plugin-loader-conformance, agent-skill-hidden-instruction-trust, cursor-mcpoison-config-risk, pwn-request-scanner
CWE-862 mcp-client-untrusted-annotation-approval
CWE-863 coding-agent-deny-rule-reachability, mcp-method-desync
CWE-915 mass-assignment-update
CWE-918 dns-rebinding-attack
CWE-943 elasticsearch-query-injection, mongodb-injection-deep
CWE-1007 mcp-invisible-unicode-poisoning
CWE-1008 example-http-check
CWE-1188 coding-agent-cross-tool-config-bleed, coding-agent-repo-config-autoexec, coding-agent-repo-config-credential-redirect
CWE-1289 mcp-client-mrtr-conformance
CWE-1336 ssti-engine-fingerprint
CWE-1427 agent-skill-hidden-instruction-trust, mcp-invisible-unicode-poisoning, mcp-tool-poisoning
N/A port-scanner-async, system-context-recon

These declare no @cwe. The field is optional, and nothing refuses to run a template without one, so this is a description of the corpus rather than a list of faults.

Check Category
etcd-auth-check devops
etcd-instead-http-request devops
etcd-think-path-wrong devops
etcd-unauth devops
etcd-unauthenticated-access devops
http-header-injection web
http-service-responding network
password-reset-takeover web
postgresql-extension-rce databases
prometheus-node-exporter-exposed monitoring
prototype-pollution web
runner-token-detection devops
saml-sso-bypass-gitlab devops
server-side-js-injection web
websocket-message-fuzzer network