FixV2W: Correcting Invalid CVE-CWE Mappings with Knowledge Graph Embeddings
arXiv cs.LG / 4/27/2026
💬 OpinionDeveloper Stack & InfrastructureIdeas & Deep AnalysisModels & Research
Key Points
- The paper highlights that CVE-to-CWE mappings in public sources like the NVD can be inconsistent or incomplete, which undermines automated vulnerability analysis and remediation.
- It introduces FixV2W, a lightweight method that uses knowledge graph embeddings plus historical remapping trends and hierarchical relationships in NVD/CWE data to predict more accurate CWE mappings.
- FixV2W targets vulnerabilities whose CWE links fall under Prohibited or Discouraged categories, using longitudinal patterns to correct previously invalid mappings.
- In experiments on data collected from Aug 2021 to Dec 2024, FixV2W correctly predicts the right CWE for 69% of exploited vulnerabilities that had invalid CWE assignments before exploitation.
- The approach also boosts downstream ML performance, improving Mean Reciprocal Rank (MRR) for an ML model focused on finding unknown CVE-CWE mappings from 0.174 to 0.608.
Related Articles

Legal Insight Transformation: 7 Mistakes to Avoid When Adopting AI Tools
Dev.to

Legal Insight Transformation: Traditional vs. AI-Driven Research Compared
Dev.to

Legal Insight Transformation: A Beginner's Guide to Modern Research
Dev.to
The Open Source AI Studio That Nobody's Talking About
Dev.to

How I Built a 10-Language Sports Analytics Platform with FastAPI, SQLite, and Claude AI (As a Solo Non-Technical Founder)
Dev.to