Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cwe-tool — A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration. | Kitploit
Tools/GitHubGitHub/owasp/cwe-tool
Static AnalysisVulnerability AnalysisCode AnalysisUtilities & FrameworksLearning & EducationCurated Resources
GitHubowasp/cwe-tool

cwe-tool

A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.

View Repository
6422155 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

cwe-tool

A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.
Official OWASP CWE Toolkit Page

npm version license downloads build codecov Known Vulnerabilities Responsible Disclosure Policy

Install

Executable with Node.js tooling

If you have a Node.js environment, you can invoke cwe-tool using the npx tool as follows:

npx cwe-tool [...command-line options...]

Docker

Pull the image from Docker Hub

docker pull lirantal/cwe-tool
docker run --rm lirantal/cwe-tool --search test

Local build instructions

git clone https://github.com/OWASP/cwe-tool
docker build -t docker.pkg.github.com/owasp/cwe-tool/cwe-tool . 

-t image name above can be an image name of your choosing!

Run examples with Docker

docker run --rm docker.pkg.github.com/owasp/cwe-tool/cwe-tool --id 22
docker run --rm docker.pkg.github.com/owasp/cwe-tool/cwe-tool --search test

Do not want to build locally? Pull the image down

Pull image from Github package registry and run a search

docker pull docker.pkg.github.com/owasp/cwe-tool/cwe-tool:latest
docker run --rm docker.pkg.github.com/owasp/cwe-tool/cwe-tool:latest --search test

Usage

The CWE Tool output is JSON to allow processing of the data or later investigations.

Command-line options blueprint:

command-line argumentdescriptionimplemented
--idGet a CWE data by its ID.✅
--parent-idWhen both --id and --parent-id are provided, returns only CWE ids which satisfy the parent id.✅ PRs welcome
--indirectWhen specified along with --parent-id, retrieves all indirect parents up to the root of the tree.✅
--searchString search returns all the matching CWEs titles✅
--show-membershipReturns all the CWE IDs along with their CWE Category membership relations❌ PRs welcome

Example

Get CWE By ID

npx cwe-tool --id 22

Filter for CWE IDs that satisfy a parent relationship

The following command filters all CWE IDs based on whether they satisfy any direct or indirect relationship across the tree to a given parent ID.

npx cwe-tool --id 22 --parent-id 167 --indirect

The output is the following JSON:

Download Tool