Weaknesses of type CWE-829

244 results

Inclusão de funcionalidade de esfera de controle não confiável

Ocorre quando o software importa, carrega ou executa código, bibliotecas ou componentes originários de uma fonte não confiável ou não verificada. O atacante consegue injetar funcionalidade maliciosa que rodará com os mesmos privilégios da aplicação, comprometendo a integridade e segurança do sistema.

Example

Uma aplicação web baixa dinamicamente um plugin ou módulo de um servidor externo sem validar assinatura criptográfica ou integridade. Um atacante intercepta ou compromete o servidor de origem e substitui o arquivo legítimo por uma versão maliciosa; a aplicação carrega e executa o código comprometido automaticamente.

How to mitigate

Valide sempre a origem, autenticidade e integridade de componentes antes de carregá-los: use assinatura digital criptográfica, checksums verificados, HTTPS com pinning de certificado e, quando possível, evite carregamento dinâmico. Mantenha inventário atualizado de dependências e aplique patches regularmente.

CVE-2025-68162LOWIn JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configurationEPSS 0.2%CVE-2026-40156HIGHPraisonAI Affected by Implicit Execution of Arbitrary Code via Automatic `tools.py` LoadingEPSS 0.2%CVE-2026-27615HIGHADB-Explorer: UNC Path Support in ManualAdbPath Leads to Remote Code Execution (RCE)EPSS 0.2%CVE-2026-4295HIGHArbitrary code execution via crafted project files in Kiro IDEEPSS 0.2%CVE-2026-13751MEDIUMSnowflake CLI Server-Side Request Forgery via Arbitrary URL Fetch in !source/!loadEPSS 0.2%CVE-2022-49038HIGHInclusion of functionality from untrusted control sphere vulnerability in OpenSSL DLL component in Synology Drive Client before 3.3.0-15082 EPSS 0.2%CVE-2026-52858HIGHVim: Arbitrary Code Execution via Python Omni-CompletionEPSS 0.2%CVE-2026-41253MEDIUMIn iTerm2 through 3.6.9, displaying a .txt file can cause code execution via DCS 2000p and OSC 135 data, if the working directory contains aEPSS 0.2%CVE-2024-52976MEDIUMElastic Agent Inclusion of Functionality from Untrusted Control SphereEPSS 0.2%CVE-2026-3991HIGHElevation of Privileges in Symantec Data Loss Prevention Windows EndpointEPSS 0.2%CVE-2026-81305HIGHCareCam CM2507 Inclusion of Functionality from Untrusted Control SphereEPSS 0.2%CVE-2026-57860HIGHForgeCode Arbitrary Code Execution via Unvetted .mcp.json in Untrusted RepositoryEPSS 0.2%CVE-2026-64806HIGHIn JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpretEPSS 0.2%CVE-2026-64805HIGHIn JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager toEPSS 0.2%CVE-2026-64808HIGHIn JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project toolingEPSS 0.2%CVE-2026-64804HIGHIn JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter toolingEPSS 0.2%CVE-2026-64809HIGHIn JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreterEPSS 0.2%CVE-2026-55697HIGHpnpm: Repository-controlled configDependencies can select a pacquet native install engineEPSS 0.2%CVE-2026-4255HIGHDLL Injection Privilege EscalationEPSS 0.2%CVE-2025-52655LOWHCL MyXalytics is affected by a Cross-Domain Script Include vulnerability.EPSS 0.2%