Value of enriching sparse CLI-SAST findings with CWE/CVE data
Determine whether retrieving information from Common Weakness Enumeration and Common Vulnerabilities and Exposures databases provides valuable additional detail for issues generated from command-line-only SAST tools that report little beyond a CWE or CVE reference.
References
Some of these CLI tools provide little to no detail on the issues they uncover, except for a reference to their corresponding CWE or CVE. We will investigate whether retrieving data from the CWE/CVE databases to fill out more information in these issues would be valuable.
— Automating Static Code Analysis Through CI/CD Pipeline Integration
(2609.00676 - Wadhams et al., 1 Sep 2026) in Section 7, Conclusion and Future Work