CVE Object Reference
The CVE object is the canonical data structure returned by all CVE detail endpoints.
Top-Level Fields
| Field | Type | Description |
|---|---|---|
| cve_id | string | CVE identifier (CVE-YYYY-NNNNN) |
| bsid | string | BreachSpider unique ID (BS-YYYY-NNNNNN-S) |
| title | string | Vulnerability title |
| description | string | Full vulnerability description |
| scoring | object | All scoring data (CVSS, EPSS, BCS) |
| exploitation | object | Active exploitation signals |
| affected | object | Affected vendors, products, protocols |
| patch | object | Patch availability and details |
| classification | object | CWEs, attack vector, layer |
| capec | array | CAPEC attack patterns inherited through the CVE's CWEs |
| sage | object | AI analysis |
| temporal | object | All timestamps |
| references | object | External URLs |
| _links | object | HATEOAS navigation links |
scoring Object
scoring.cvss
| Field | Type | Example |
|---|---|---|
| score | float | 10.0 |
| vector | string | CVSS:3.1/AV:N/AC:L/... |
| version | string | 3.1 |
| severity | string | CRITICAL |
| attack_vector | string | NETWORK |
| attack_complexity | string | LOW |
| privileges_required | string | NONE |
| user_interaction | string | NONE |
| scope | string | CHANGED |
| confidentiality_impact | string | HIGH |
| integrity_impact | string | HIGH |
| availability_impact | string | HIGH |
scoring.epss
| Field | Type | Description |
|---|---|---|
| score | float | 0.0-1.0 probability of exploitation |
| percentile | float | 0.0-1.0 relative to all CVEs |
| interpretation | string | Human-readable percentile label |
scoring.bcs
BCS (BreachSpider Confidence Score) is BreachSpider's proprietary exploitation priority score combining CVSS, EPSS, KEV status, PoC availability, and ICS relevance.
| Field | Type | Description |
|---|---|---|
| score | float | 0.0-10.0 |
| tier | string | CRITICAL, HIGH, MEDIUM, LOW |
| factors.kev_flagged | boolean | In KEV catalog |
| factors.poc_available | boolean | Public PoC exists |
| factors.has_public_exploit | boolean | Functional exploit public |
| factors.patch_available | boolean | Vendor patch released |
| factors.ics_relevance | float | 0.0-1.0 ICS/OT relevance score |
exploitation Object
| Field | Type | Description |
|---|---|---|
| kev_flagged | boolean | KEV-confirmed active exploitation |
| kev_added_at | string | ISO 8601 date added to KEV |
| has_public_exploit | boolean | Functional exploit publicly available |
| poc_available | boolean | Proof-of-concept code available |
| exploit_maturity | string | NONE, POC, FUNCTIONAL, WEAPONIZED |
| actively_exploited | boolean | True when kev_flagged is true |
Exploit Maturity Tiers
| Maturity | Meaning |
|---|---|
| NONE | No exploit or PoC available |
| POC | Proof-of-concept code published |
| FUNCTIONAL | Working exploit available |
| WEAPONIZED | On the CISA KEV catalog with no public exploit or PoC recorded. A KEV CVE with a public exploit reads FUNCTIONAL; check kev_flagged for known exploitation |
affected Object
| Field | Type | Description |
|---|---|---|
| vendors | array | List of affected vendor names |
| products | array | Reserved: currently always empty |
| primary_vendor | string | Reserved: currently always null |
| primary_product | string | Reserved: currently always null |
| vendor_count | integer | Total number of affected vendors |
| device_types | array | ICS device type classifications |
| protocols | array | Affected ICS protocols |
| ics_relevance_score | float | 0.0-1.0 ICS/OT relevance |
| ics_relevant | boolean | True when ics_relevance_score >= 0.5 or the CVE is linked to an industrial protocol |
patch Object
| Field | Type | Description |
|---|---|---|
| status | string | patched, unpatched, partial, workaround, unknown |
| patch_available | boolean | True when status is patched |
| patch_version | string | Fixed version (if known) |
| patch_url | string | Link to patch download (if known) |
| patch_notes | string | Remediation notes |
sage Object
| Field | Type | Description |
|---|---|---|
| model | string | AI model version |
| tier | string | full or blurred |
| executive_summary | string | AI-generated summary (all tiers) |
| ics_context | string | ICS/OT specific context (full tier) |
| remediation_guidance | string | Remediation steps (full tier) |
| confidence_score | float | AI confidence 0.0-1.0 (full tier) |
| confidence_tier | string | SOVEREIGN_AUDIT_PASS or lower |
| _upgrade_required | boolean | True when tier is blurred |
| _upgrade_url | string | Upgrade URL when blurred |
temporal Object
| Field | Type | Description |
|---|---|---|
| published_at | string | NVD publication date (ISO 8601) |
| modified_at | string | Last NVD modification date |
| enriched_at | string | BreachSpider enrichment timestamp |
| kev_added_at | string | Date added to KEV catalog |
capec Object
CAPEC attack-pattern enrichment (Tier 1). Every CVE that carries a CWE weakness also carries the CAPEC attack patterns MITRE relates to that CWE. This gives attack-pattern context per CVE without any per-CVE labeling. It is built entirely from the CWE data already held plus the published MITRE CAPEC catalog.
capec is an array deduplicated by capec_id. It is always present: an empty array (never null) when the CVE has no related CAPEC.
| Field | Type | Description |
|---|---|---|
| capec_id | integer | CAPEC attack-pattern identifier |
| name | string | CAPEC attack-pattern name |
| slug | string | URL slug, capec-{capec_id} |
| typical_severity | string | MITRE typical severity for the pattern |
| via_cwe | array | Bridging CWE ids that cite this mapping |
via_cwe is the citation anchor. It names the CWE (or CWEs) on the CVE that MITRE maps to the attack pattern. When one attack pattern is reachable through more than one bridging CWE, the CAPEC appears once with every bridging CWE listed.
Sources
CAPEC enrichment uses the MITRE CAPEC catalog (version 3.9, 615 attack patterns) and MITRE's own CWE-to-CAPEC relationships (1,154 pairs). Each attack pattern is stamped with its catalog version and a checksum, so the exact release behind any pattern is auditable. For each CVE, the CWE weaknesses it lists are followed to the attack patterns MITRE maps to them; each pattern appears once, with every bridging CWE in via_cwe. MITRE's CAPEC-to-ATT&CK technique mappings are held but not yet exposed through the API.
Provenance and Correctness
The CWE-to-CAPEC relationship is authoritative and published by MITRE. It is not inferred by BreachSpider. It can be presented as a real mapping, cited by the bridging CWE.
This is distinct from any future ATT&CK derivation. Deriving ATT&CK from a CVE would chain a second inference on top of the CWE-to-CAPEC mapping, so when that step is built it must be labeled as derived. Authoritative CWE-to-CAPEC data and derived ATT&CK data are not the same, and derived ATT&CK must never be presented as authoritative.
Coverage
228,000 plus distinct CVEs return a non-empty capec array, which is 63 percent of the CVE base.
The honest gap: CWE coverage is 79 percent and CAPEC-inherited coverage is 63 percent. The difference is CWEs that MITRE CAPEC does not map to any attack pattern, plus 29 CAPEC-referenced hardware-class CWEs (CWE-1000 and up) that are absent from the current cwes set. This is the shape of MITRE's published data, not a defect in the enrichment.
Refreshing the Catalog
To refresh, re-run the Tier 1 ingest against a newer capec_latest.xml. The ingest is idempotent, so a re-run updates the catalog version and adds any new patterns without duplicating existing rows.