Weaknesses of type CWE-829

244 results

Inclusão de funcionalidade de esfera de controle não confiável

Ocorre quando o software importa, carrega ou executa código, bibliotecas ou componentes originários de uma fonte não confiável ou não verificada. O atacante consegue injetar funcionalidade maliciosa que rodará com os mesmos privilégios da aplicação, comprometendo a integridade e segurança do sistema.

Example

Uma aplicação web baixa dinamicamente um plugin ou módulo de um servidor externo sem validar assinatura criptográfica ou integridade. Um atacante intercepta ou compromete o servidor de origem e substitui o arquivo legítimo por uma versão maliciosa; a aplicação carrega e executa o código comprometido automaticamente.

How to mitigate

Valide sempre a origem, autenticidade e integridade de componentes antes de carregá-los: use assinatura digital criptográfica, checksums verificados, HTTPS com pinning de certificado e, quando possível, evite carregamento dinâmico. Mantenha inventário atualizado de dependências e aplique patches regularmente.

CVE-2026-33075CRITICALFastGPT has Arbitrary Code Execution in GitHub Actions via pull_request_target in fastgpt-preview-image.ymlEPSS 0.3%CVE-2026-55698HIGHpnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytesEPSS 0.3%CVE-2026-79721HIGHCode execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact toEPSS 0.3%CVE-2026-66843LOWhtml_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing untrusted content embeddingEPSS 0.3%CVE-2024-24821HIGHCode execution and possible privilege escalation via compromised InstalledVersions.php or installed.php in ComposerEPSS 0.3%CVE-2025-12509HIGHScripts for the module Global_Shipping executable on BRAIN2 ServerEPSS 0.3%CVE-2025-55305MEDIUMElectron is vulnerable to Code Injection via resource modificationEPSS 0.3%CVE-2026-96443MEDIUMApache Doris: JDBC driver URL validation bypass leads to remote code executionEPSS 0.3%CVE-2025-0982CRITICALSandbox Escape in Google Cloud Application Integration's JavaScript Task (Rhino Engine)EPSS 0.3%CVE-2026-73367HIGHWordPress Easy Google Maps plugin < 1.14.2 - Remote File Inclusion vulnerabilityEPSS 0.2%CVE-2026-40903CRITICALGoshs - ArtiPACKED Vulnerability – GitHub Actions Credential PersistenceEPSS 0.2%CVE-2025-36852CRITICALBuild Cache Poisoning via Untrusted Pull RequestsEPSS 0.2%CVE-2025-55273MEDIUMHCL Aftermarket DPC is affected by Cross Domain Script Include vulnerabilityEPSS 0.2%CVE-2026-28135HIGHWordPress Royal Elementor Addons plugin <= 1.7.1052 - Other vulnerability Type vulnerabilityEPSS 0.2%CVE-2026-5817HIGHDocker Model Runner container-to-host code execution via unsandboxed trust_remote_code in Python inference backendsEPSS 0.2%CVE-2026-5843HIGHDocker Model Runner container-to-host code execution via MLX-LM model_file importlib loadingEPSS 0.2%CVE-2026-34442MEDIUMFreeScout: Host Header Injection Leading to External Resource Loading and Open Redirect in FreeScoutEPSS 0.2%CVE-2025-15612MEDIUMWazuh Provisioning Scripts / Build Infrastructure Improper Certificate Validation leading to MITM and RCEEPSS 0.2%CVE-2026-50562CRITICALFastGPT: Untrusted PR artifacts are pushed and deployed by privileged preview workflowsEPSS 0.2%CVE-2026-22283HIGHDell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Inclusion of Functionality from Untrusted Control Sphere vulnerability. AEPSS 0.2%