CIRCL/vulnerability-cwe-patch
Description This dataset, CIRCL/vulnerability-cwe-patch, provides structured, real-world vulnerabilities enriched with CWE identifiers and corresponding patches from platforms like GitHub and GitLab. It is designed to support the development of tools for vulnerability classification, triage, and automated remediation. Each entry includes metadata such as CVE/GHSA ID, a description, CWE categorization, and links to verified patch commits with associated diff content and commit… See the full description on the dataset page: https://huggingface.co/datasets/CIRCL/vulnerability-cwe-patch.
5517
1---2dataset_info:3 features:4 - name: id5 dtype: string6 - name: title7 dtype: string8 - name: description9 dtype: string10 - name: patches11 list:12 - name: url13 dtype: string14 - name: patch_text_b6415 dtype: string16 - name: commit_message17 dtype: string18 - name: cwe19 list: string20 splits:21 - name: train22 num_bytes: 11738743823 num_examples: 156824 - name: test25 num_bytes: 1310127626 num_examples: 17527 download_size: 13034987528 dataset_size: 13048871429configs:30- config_name: default31 data_files:32 - split: train33 path: data/train-*34 - split: test35 path: data/test-*36---37 38### Description39 40This dataset, CIRCL/vulnerability-cwe-patch, provides structured, real-world vulnerabilities enriched with CWE identifiers and corresponding patches from platforms like GitHub and GitLab. It is designed to support the development of tools for vulnerability classification, triage, and automated remediation. Each entry includes metadata such as CVE/GHSA ID, a description, CWE categorization, and links to verified patch commits with associated diff content and commit messages.41 42The dataset is automatically extracted via a pipeline that fetches vulnerability records from multiple sources, filters out entries without patches, and verifies the accessibility of patch links. Patches are then fetched, base64-encoded, and stored alongside commit messages for the training and evaluation of machine learning models.43 44The dataset consists of 39,260 vulnerabilities and **49,001 associated patches**. For training purposes, only patches corresponding to vulnerabilities annotated with at least one CWE are considered.45 46 47### How to use with datasets48 49```python50>>> import json51>>> from datasets import load_dataset52 53>>> dataset = load_dataset("CIRCL/vulnerability-cwe-patch")54 55>>> vulnerabilities = ["CVE-2025-60249", "CVE-2025-32413"]56 57>>> filtered_entries = dataset.filter(lambda elem: elem["id"] in vulnerabilities)58 59>>> for entry in filtered_entries["train"]:60... print(entry["cwe"])61... for patch in entry["patches"]:62... print(f" {patch['commit_message']}")63...64CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') 65 [PATCH] fix: [security] Fixed a stored XSS vulnerability in user bios. Thanks to Dawid Czarnecki for reporting the issue.66CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')67 [PATCH] fix: [security] sanitize user input in comments, bundles, and sightings - Escaped untrusted data in templates and tables to prevent XSS - Replaced unsafe innerHTML assignments with createElement/textContent - Encoded dynamic URLs using encodeURIComponent - Improved validation in Comment, Bundle, and Sighting models Credit: @Wachizungu68```69 70 71### Schema72 73Each example contains:74 75 - id: Vulnerability identifier (e.g., CVE-2023-XXXX, GHSA-XXXX)76 77 - title: Human-readable title of the vulnerability78 79 - description: Detailed vulnerability description80 81 - patches: List of patch records, each with:82 83 url: Verified patch URL (GitHub/GitLab)84 85 patch_text_b64: Base64-encoded unified diff86 87 commit_message: Associated commit message88 89 - cwe: List of CWE identifiers and names90 91 92The vulnerabilities can be sourced from:93 94 - NVD CVE List — enriched with commit references95 96 - GitHub Security Advisories (GHSA)97 98 - GitLab advisories99 100 - CSAF feeds from vendors including Red Hat, Cisco, and CISA101 102 103### Use Cases104 105The dataset supports a range of security-focused machine learning tasks:106 107 * Vulnerability classification108 109 * CWE prediction from descriptions110 111 * Patch generation from natural language112 113 * Commit message understanding114 115### Associated Code116 117The dataset is generated with the extraction pipeline from vulnerability-lookup/ML-Gateway, which includes logic for fetching, filtering, validating, and encoding patch data.