Weaknesses of type CWE-829

244 results

Inclusão de funcionalidade de esfera de controle não confiável

Ocorre quando o software importa, carrega ou executa código, bibliotecas ou componentes originários de uma fonte não confiável ou não verificada. O atacante consegue injetar funcionalidade maliciosa que rodará com os mesmos privilégios da aplicação, comprometendo a integridade e segurança do sistema.

Example

Uma aplicação web baixa dinamicamente um plugin ou módulo de um servidor externo sem validar assinatura criptográfica ou integridade. Um atacante intercepta ou compromete o servidor de origem e substitui o arquivo legítimo por uma versão maliciosa; a aplicação carrega e executa o código comprometido automaticamente.

How to mitigate

Valide sempre a origem, autenticidade e integridade de componentes antes de carregá-los: use assinatura digital criptográfica, checksums verificados, HTTPS com pinning de certificado e, quando possível, evite carregamento dinâmico. Mantenha inventário atualizado de dependências e aplique patches regularmente.

CVE-2026-44688HIGHIn Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context withEPSS 0.5%CVE-2026-46580HIGHIn Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded andEPSS 0.5%CVE-2025-24796MEDIUMRemote Code Execution within Collabora Online jail with Macros EnabledEPSS 0.5%CVE-2026-86169HIGHAxolotl before 0.19.0 Remote Code Execution via Multipack PatchingEPSS 0.5%CVE-2026-15560HIGHOpenjdk-orb: unauthed class loading via iiop in eapEPSS 0.5%CVE-2025-61592HIGHCursor CLI: Arbitrary Code Execution Possible through Permissive CLI ConfigEPSS 0.5%CVE-2026-76139HIGHAcm-operator-bundle: acm-operator-bundle: bundle build execs unpinned stolostron/release@master with full build credentialsEPSS 0.4%CVE-2022-41709HIGHMarkdownify version 1.4.1 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdoEPSS 0.4%CVE-2026-6859HIGHInstructlab: instructlab: arbitrary code execution due to hardcoded `trust_remote_code=true`EPSS 0.4%CVE-2026-66902CRITICALGoogle::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system callEPSS 0.4%CVE-2026-47292HIGHVisual Studio Code MSSQL Extension Remote Code Execution VulnerabilityEPSS 0.4%CVE-2019-10240—Eclipse hawkBit versions prior to 0.3.0M2 resolved Maven build artifacts for the Vaadin based UI over HTTP instead of HTTPS. Any of these deEPSS 0.4%CVE-2019-10248—Eclipse Vorto versions prior to 0.11 resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS. Any of these dependentEPSS 0.4%CVE-2022-31021LOWUnlinkability broken in ursa when verifiers use malicious keysEPSS 0.4%CVE-2025-36727HIGHSimpleHelp Inclusion of functionality from untrusted control sphereEPSS 0.4%CVE-2026-53810HIGHOpenClaw < 2026.5.18 - Arbitrary Code Execution via Unscanned Marketplace Runtime Extension MetadataEPSS 0.4%CVE-2026-18252HIGHInclusion of Functionality from Untrusted Control Sphere in GitLabEPSS 0.4%CVE-2026-54916HIGHNetBox Device Type Library: Module Shadowing Bypass of prior pickle fix - RCE via missing `tests/__init__.py` + SSRF via unfixed `NETBOX_DT_LIBRARY_URL` → Cloud Metadata credential theftEPSS 0.4%CVE-2026-44691HIGHIn Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be EPSS 0.4%CVE-2026-27941CRITICALOpenLIT Vulnerable to Remote Code Execution and Secret Exposure via Misuse of `pull_request_target` in GitHub Actions WorkflowsEPSS 0.4%