What is CWE (Common Weakness Enumeration)?

Security
Definition

The dictionary of software weakness types that most security tooling reports against. A finding labeled CWE-79 is a cross-site scripting flaw, and the identifier means a security team can triage it without translating a vendor's private vocabulary.

Why It Matters

A review finding is only actionable if the person reading it recognizes the class of problem. A comment that says โ€œthis function has a trust-boundary issueโ€ starts an argument. Naming CWE-502, deserialization of untrusted data, with a line number starts a fix, because the weakness class has a documented pattern, a known set of consequences, and an established remedy.

CWE gives AI-assisted review the same footing. Generated code arrives at a volume no team reads line by line, and a finding format that maps to a shared dictionary lets security teams triage by class, track recurrence, and compare what the tool claims against what the code does.

How It Works

Each weakness type carries an identifier, a description, and relationships to other entries. CWE-79 is cross-site scripting; CWE-89 is SQL injection; CWE-798 is hard-coded credentials. Tooling reports the identifier alongside the location and a suggested fix, and severity comes from an external scoring system rather than from the toolโ€™s own opinion.

The mapping matters more than the label. A finding that names a weakness class without a location or a remedy is a warning, and warnings get ignored.

Where It Breaks

CWE covers conventional software weaknesses. It does not cover the failure modes that appear when a model writes the code, chooses the tools, or acts on retrieved content. Prompt injection through a comment in a dependency, an agent granting itself broader permissions than the task needs, a tool call that succeeds with the wrong arguments: those sit in the OWASP agentic risk list, not in the CWE catalogue.

Treating a clean CWE scan as proof of safety is the other failure. Weakness classes describe what the code looks like, not whether the change was the right change or whether the tests that ran actually exercise the new path.

How Flytebit Handles It

PASSR reports every finding against its CWE class with the location, the reasoning, and a ready-to-apply fix, so a security team can triage generated code with the vocabulary it already uses. Conventional weaknesses come from the CWE mapping; agentic and supply-chain risks are handled separately by the runtime controls, since those are properties of the run rather than of the source file. The review method is documented in the AI Code Review Guide, and the industry application is on our Software & Technology page.

More info

On flytebit.com

Reviewed by Jayaveer Bhupalam, Founder & CTO Last updated September 24, 2026