Team Ai
Datasetpublic

CIRCL/vulnerability-cwe-patch

Description This dataset, CIRCL/vulnerability-cwe-patch, provides structured, real-world vulnerabilities enriched with CWE identifiers and corresponding patches from platforms like GitHub and GitLab. It is designed to support the development of tools for vulnerability classification, triage, and automated remediation. Each entry includes metadata such as CVE/GHSA ID, a description, CWE categorization, and links to verified patch commits with associated diff content and commit… See the full description on the dataset page: https://huggingface.co/datasets/CIRCL/vulnerability-cwe-patch.

sourceHugging Faceupdated 3mo agoView on Hugging Face
5likes517downloads
README.md117 linesDownload Raw Back to root
1---2dataset_info:3  features:4  - name: id5    dtype: string6  - name: title7    dtype: string8  - name: description9    dtype: string10  - name: patches11    list:12    - name: url13      dtype: string14    - name: patch_text_b6415      dtype: string16    - name: commit_message17      dtype: string18  - name: cwe19    list: string20  splits:21  - name: train22    num_bytes: 11738743823    num_examples: 156824  - name: test25    num_bytes: 1310127626    num_examples: 17527  download_size: 13034987528  dataset_size: 13048871429configs:30- config_name: default31  data_files:32  - split: train33    path: data/train-*34  - split: test35    path: data/test-*36---37 38### Description39 40This dataset, CIRCL/vulnerability-cwe-patch, provides structured, real-world vulnerabilities enriched with CWE identifiers and corresponding patches from platforms like GitHub and GitLab. It is designed to support the development of tools for vulnerability classification, triage, and automated remediation. Each entry includes metadata such as CVE/GHSA ID, a description, CWE categorization, and links to verified patch commits with associated diff content and commit messages.41 42The dataset is automatically extracted via a pipeline that fetches vulnerability records from multiple sources, filters out entries without patches, and verifies the accessibility of patch links. Patches are then fetched, base64-encoded, and stored alongside commit messages for the training and evaluation of machine learning models.43 44The dataset consists of 39,260 vulnerabilities and **49,001 associated patches**. For training purposes, only patches corresponding to vulnerabilities annotated with at least one CWE are considered.45 46 47### How to use with datasets48 49```python50>>> import json51>>> from datasets import load_dataset52 53>>> dataset = load_dataset("CIRCL/vulnerability-cwe-patch")54 55>>> vulnerabilities = ["CVE-2025-60249", "CVE-2025-32413"]56 57>>> filtered_entries = dataset.filter(lambda elem: elem["id"] in vulnerabilities)58 59>>> for entry in filtered_entries["train"]:60...     print(entry["cwe"])61...     for patch in entry["patches"]:62...         print(f"  {patch['commit_message']}")63...64CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')     65  [PATCH] fix: [security] Fixed a stored XSS vulnerability in user bios. Thanks to Dawid Czarnecki for reporting the issue.66CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')67  [PATCH] fix: [security] sanitize user input in comments, bundles, and sightings - Escaped untrusted data in templates and tables to prevent XSS - Replaced unsafe innerHTML assignments with createElement/textContent - Encoded dynamic URLs using encodeURIComponent - Improved validation in Comment, Bundle, and Sighting models Credit: @Wachizungu68```69 70 71### Schema72 73Each example contains:74 75    - id: Vulnerability identifier (e.g., CVE-2023-XXXX, GHSA-XXXX)76 77    - title: Human-readable title of the vulnerability78 79    - description: Detailed vulnerability description80 81    - patches: List of patch records, each with:82 83        url: Verified patch URL (GitHub/GitLab)84 85        patch_text_b64: Base64-encoded unified diff86 87        commit_message: Associated commit message88 89    - cwe: List of CWE identifiers and names90 91 92The vulnerabilities can be sourced from:93 94    - NVD CVE List — enriched with commit references95 96    - GitHub Security Advisories (GHSA)97 98    - GitLab advisories99 100    - CSAF feeds from vendors including Red Hat, Cisco, and CISA101 102 103### Use Cases104 105The dataset supports a range of security-focused machine learning tasks:106 107    * Vulnerability classification108    109    * CWE prediction from descriptions110    111    * Patch generation from natural language112    113    * Commit message understanding114 115### Associated Code116 117The dataset is generated with the extraction pipeline from vulnerability-lookup/ML-Gateway, which includes logic for fetching, filtering, validating, and encoding patch data.