
A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.
A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.
Official OWASP CWE Toolkit Page
If you have a Node.js environment, you can invoke cwe-tool using the npx tool as follows:
npx cwe-tool [...command-line options...]
docker pull lirantal/cwe-tool
docker run --rm lirantal/cwe-tool --search test
git clone https://github.com/OWASP/cwe-tool
docker build -t docker.pkg.github.com/owasp/cwe-tool/cwe-tool .
-t image name above can be an image name of your choosing!
Run examples with Docker
docker run --rm docker.pkg.github.com/owasp/cwe-tool/cwe-tool --id 22
docker run --rm docker.pkg.github.com/owasp/cwe-tool/cwe-tool --search test
Pull image from Github package registry and run a search
docker pull docker.pkg.github.com/owasp/cwe-tool/cwe-tool:latest
docker run --rm docker.pkg.github.com/owasp/cwe-tool/cwe-tool:latest --search test
The CWE Tool output is JSON to allow processing of the data or later investigations.
Command-line options blueprint:
| command-line argument | description | implemented |
|---|---|---|
--id | Get a CWE data by its ID. | ✅ |
--parent-id | When both --id and --parent-id are provided, returns only CWE ids which satisfy the parent id. | ✅ PRs welcome |
--indirect | When specified along with --parent-id, retrieves all indirect parents up to the root of the tree. | ✅ |
--search | String search returns all the matching CWEs titles | ✅ |
--show-membership | Returns all the CWE IDs along with their CWE Category membership relations | ❌ PRs welcome |
npx cwe-tool --id 22
The following command filters all CWE IDs based on whether they satisfy any direct or indirect relationship across the tree to a given parent ID.
npx cwe-tool --id 22 --parent-id 167 --indirect
The output is the following JSON: