Weaknesses of type CWE-829

245 results

Inclusão de funcionalidade de esfera de controle não confiável

Ocorre quando o software importa, carrega ou executa código, bibliotecas ou componentes originários de uma fonte não confiável ou não verificada. O atacante consegue injetar funcionalidade maliciosa que rodará com os mesmos privilégios da aplicação, comprometendo a integridade e segurança do sistema.

Example

Uma aplicação web baixa dinamicamente um plugin ou módulo de um servidor externo sem validar assinatura criptográfica ou integridade. Um atacante intercepta ou compromete o servidor de origem e substitui o arquivo legítimo por uma versão maliciosa; a aplicação carrega e executa o código comprometido automaticamente.

How to mitigate

Valide sempre a origem, autenticidade e integridade de componentes antes de carregá-los: use assinatura digital criptográfica, checksums verificados, HTTPS com pinning de certificado e, quando possível, evite carregamento dinâmico. Mantenha inventário atualizado de dependências e aplique patches regularmente.

CVE-2026-44995MEDIUMOpenClaw < 2026.4.20 - Arbitrary Code Execution via MCP stdio Environment VariablesEPSS 0.1%CVE-2026-41336HIGHOpenClaw < 2026.3.31 - Arbitrary Hook Code Execution via OPENCLAW_BUNDLED_HOOKS_DIR Environment Variable OverrideEPSS 0.1%CVE-2026-8428HIGHCSRF token is not validated in the core CMS update controller for Concrete CMS 9.5.0 and belowEPSS 0.1%CVE-2026-41295HIGHOpenClaw < 2026.4.2 - Untrusted Workspace Channel Shadow Code Execution during Built-in Channel SetupEPSS 0.1%CVE-2026-73076HIGHVim: Arbitrary Command Execution via Malicious `.VimballRecord` Entry Replay in `vimball.vim`EPSS 0.1%CVE-2026-47781HIGHpdm: Project-Controlled `.pdm-plugins` Content Executes Before CLI ParsingEPSS 0.1%CVE-2026-19884HIGHIn Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integration without requiring the user to trustEPSS 0.1%CVE-2026-12057HIGHDoS + Remote Code Execution via PDF JavaScript in Foxit AIEPSS 0.1%CVE-2025-57729MEDIUMIn JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server startEPSS 0.1%CVE-2026-25931HIGHvscode-spell-checker has a workspace-trust bypass Code ExecutionEPSS 0.1%CVE-2026-58569HIGHDell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An authenticated user with limited priviEPSS 0.1%CVE-2026-0303LOWCheckov by Prisma Cloud: Code Execution via Auto-Loaded Configuration FileEPSS 0.1%CVE-2026-86504HIGHIn JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code executEPSS 0.1%CVE-2026-49449LOWJoplin: KaTeX `trust:true` enables URL-allowlist bypass leading to NTLMv2 credential theft via UNC path on WindowsEPSS 0.1%CVE-2026-64811HIGHIn JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container confiEPSS 0.1%CVE-2026-41396HIGHOpenClaw < 2026.3.31 - Environment Variable Override of Plugin Trust RootEPSS 0.1%CVE-2026-22217MEDIUMOpenClaw 2026.2.22 < 2026.2.23 - Arbitrary Binary Execution via $SHELL Environment Variable Trusted Prefix FallbackEPSS 0.1%CVE-2022-49036HIGHAn inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business ReEPSS 0.1%CVE-2026-41355MEDIUMOpenClaw < 2026.3.28 - Arbitrary Code Execution via Mirror Mode Sandbox File ConversionEPSS 0.1%CVE-2022-49042HIGHAn inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.EPSS 0.1%