Cyber Resilience

CWE · MITRE source

CWE-96Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')

Abstraction: Base · CVEs in our corpus: 23

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before inserting the input into an executable resource, such as a library, configuration file, or template.

Last updated: 20 August 2026 13:14 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: partial · 2 mapping(s) from 1 framework(s): CAPEC 2 (partial)

See the full cumulative-coverage rollup →

OWASP Top 10 for Web (2025)

This weakness contributes to A05:2025 Injection.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • SC-34 Non-modifiable Executable Programs
  • PR.PS-06
  • SA-11 Developer Testing and Evaluation
  • SI-10 Information Input Validation
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V1.3.2

NIST 800-53 r5 controls that address this weakness (1)AI-assisted

Control Title Family Why it addresses this CWE
SC-34Non-modifiable Executable ProgramsSCEliminates the possibility of static code injection into saved executables by making the storage non-modifiable.

MITRE ATT&CK techniques this weakness enables

Our own two-way CWE↔ATT&CK cross-walk — a direct mapping with no public source (the CWE→CAPEC→ATT&CK chain leaves most top weaknesses, incl. XSS and SQLi, mapped to nothing).

Direction: other covers this; this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2020-6143 8.09.80.06172020-09-01
CVE-2020-6144 8.09.80.06172020-09-01
CVE-2022-43938 8.08.80.26442023-04-03
CVE-2022-0895 7.69.80.01752022-03-10
CVE-2023-39726 7.59.80.01032023-10-26
CVE-2024-55877 7.39.90.01562024-12-12
CVE-2024-13264 7.39.80.00462025-01-09
CVE-2015-2079 7.29.90.01462025-04-28
CVE-2024-55662 7.19.90.00762024-12-12
CVE-2025-577076.68.80.00662026-02-11
CVE-2024-434006.49.00.00492024-08-19
CVE-2024-32487 6.18.60.00632024-04-13
CVE-2024-37900 6.16.40.15802024-07-31
CVE-2021-39115 6.07.20.04482021-09-01
CVE-2024-13265 5.87.50.00562025-01-09
CVE-2024-13267 5.87.50.00562025-01-09
CVE-2025-36595 5.57.20.00552025-06-27
CVE-2024-13268 5.36.80.00472025-01-09
CVE-2022-3960 5.06.30.00452023-04-03
CVE-2024-0788 5.06.60.00242024-01-29
CVE-2025-7825 4.86.30.00252025-10-03
CVE-2024-13263 4.35.50.00262025-01-09