Weaknesses of type CWE-829

244 results

Inclusão de funcionalidade de esfera de controle não confiável

Ocorre quando o software importa, carrega ou executa código, bibliotecas ou componentes originários de uma fonte não confiável ou não verificada. O atacante consegue injetar funcionalidade maliciosa que rodará com os mesmos privilégios da aplicação, comprometendo a integridade e segurança do sistema.

Example

Uma aplicação web baixa dinamicamente um plugin ou módulo de um servidor externo sem validar assinatura criptográfica ou integridade. Um atacante intercepta ou compromete o servidor de origem e substitui o arquivo legítimo por uma versão maliciosa; a aplicação carrega e executa o código comprometido automaticamente.

How to mitigate

Valide sempre a origem, autenticidade e integridade de componentes antes de carregá-los: use assinatura digital criptográfica, checksums verificados, HTTPS com pinning de certificado e, quando possível, evite carregamento dinâmico. Mantenha inventário atualizado de dependências e aplique patches regularmente.

CVE-2026-54981HIGHVisual Studio Code Python Extension Security Feature Bypass VulnerabilityEPSS 0.4%CVE-2023-31168MEDIUM Inclusion of Functionality from Untrusted Control SphereEPSS 0.4%CVE-2026-44484CRITICALCompromise of PyTorch Lightning PyPi Package VersionsEPSS 0.4%CVE-2024-32011HIGHA vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to run EPSS 0.4%CVE-2026-43571HIGHOpenClaw < 2026.4.10 - Untrusted Workspace Plugin Shadow Resolution in Channel SetupEPSS 0.4%CVE-2022-46302HIGHRemote Code Execution with Root Privileges via Broad Apache PermissionsEPSS 0.4%CVE-2026-43569HIGHOpenClaw < 2026.4.9 - Untrusted Provider Plugin Auto-enablement via Workspace Provider AuthEPSS 0.4%CVE-2026-8879HIGHCVE-2026-8879EPSS 0.4%CVE-2026-28372HIGHtelnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added EPSS 0.4%CVE-2026-45272CRITICALMyBooks: Remote Code Execution via SOCIAL_AUTH Key Name Injection in Python Config FileEPSS 0.4%CVE-2026-13745HIGHArbitrary Code Execution in Gemini CLI via Untrusted Local .env Files Overriding GEMINI_CLI_HOMEEPSS 0.4%CVE-2025-59828HIGHClaude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn VersionsEPSS 0.4%CVE-2026-26862HIGHCleverTap Web SDK version 1.15.2 and earlier is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage in the Visual BuilEPSS 0.4%CVE-2026-18408HIGHPostgreSQL psql \unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql clientEPSS 0.4%CVE-2026-43944CRITICALelecterm: dangerous code can be run through links or command lineEPSS 0.4%CVE-2025-70046CRITICALAn issue pertaining to CWE-829: Inclusion of Functionality from Untrusted Control Sphere was discovered in Miazzy oa-front-service master.EPSS 0.4%CVE-2026-6464HIGHPostgreSQL psql COPY FROM STDIN early failure processes data lines as psql commandsEPSS 0.4%CVE-2025-67842MEDIUMThe Static Asset API in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HTML via the subdomainEPSS 0.4%CVE-2026-54752CRITICALNetBox Device Type Library: Insecure Pickle Deserialization in Test Suite Allows Remote Code Execution via Malicious Pull RequestEPSS 0.4%CVE-2026-15519LOWusestrix PyPI system_prompt.jinja inclusion of functionality from untrusted control sphereEPSS 0.3%