Fallos del tipo CWE-829

242 resultados

Inclusão de funcionalidade de fonte não confiável

Ocorre quando uma aplicação carrega ou executa código, bibliotecas ou componentes originários de uma fonte não verificada ou controlada por terceiros. O risco é alto porque o código malicioso ou comprometido executa com os mesmos privilégios da aplicação, permitindo roubo de dados, injeção de código ou compromisso total do sistema.

Ejemplo

Um aplicativo web busca um script JavaScript de um CDN externo sem validar assinatura criptográfica. Se o CDN for comprometido ou o tráfego interceptado, o atacante injeta código que rouba credenciais dos usuários. Outro caso: uma dependência npm instalada automaticamente é atualizada e passa a conter malware, afetando todos os projetos que a consomem.

Cómo mitigar

Valide a origem e integridade de componentes: use subresource integrity (SRI) para scripts externos, verifique assinaturas digitais de pacotes, mantenha dependências em repositório privado controlado, e audite regularmente bibliotecas críticas com ferramentas como npm audit ou SBOM. Implemente listas de permissão (whitelist) de fontes confiáveis e isole a execução quando possível.

CVE-2026-56447CRITICALMISP remote code execution via arbitrary rdkafka configuration pathEPSS 0.6%CVE-2026-93993HIGHMistral Vibe before 2.25.5 Remote Code Execution via git post-checkoutEPSS 0.6%CVE-2024-54663HIGHAn issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Inclusion (LFI) vulnerabEPSS 0.6%CVE-2024-43690HIGHInclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allow an attacker to perEPSS 0.6%CVE-2026-5241HIGHPolicy Bypass in LightGlue Nested Config Resolution in huggingface/transformersEPSS 0.6%CVE-2023-41267Apache HDFS Provider error message suggested installation of incorrect pip packageEPSS 0.6%CVE-2024-5693MEDIUMOffscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of saEPSS 0.6%CVE-2026-47398HIGHPraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334EPSS 0.6%CVE-2026-42510MEDIUMOpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.EPSS 0.6%CVE-2026-26974HIGHSylde has Improper Control of Generation of CodeEPSS 0.6%CVE-2024-45416HIGHThe HTTPD binary in multiple ZTE routers has a local file inclusion vulnerability in session_init function. The session -LUA- files are storEPSS 0.6%CVE-2020-36924MEDIUMSony BRAVIA Digital Signage 1.7.8 Unauthenticated Remote File InclusionEPSS 0.5%CVE-2022-31156MEDIUMGradle's dependency verification can ignore checksum verification when signature verification cannot be performedEPSS 0.5%CVE-2025-11023CRITICALLocal File Inclusion in ArkSigner's AcBakImzalaEPSS 0.5%CVE-2024-3043HIGHZigbee co-ordinator realignment packet may lead to denial of serviceEPSS 0.5%CVE-2026-46529HIGHPDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopenEPSS 0.5%CVE-2026-67623HIGHMistral Vibe < 2.23.3 Arbitrary Command Execution via git fsmonitor HookEPSS 0.5%CVE-2026-1699CRITICALIn the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_target trigger while chEPSS 0.5%CVE-2024-48336HIGHThe install() function of ProviderInstaller.java in Magisk App before canary version 27007 does not verify the GMS app before loading it, whEPSS 0.5%CVE-2020-36905MEDIUMFIBARO System Home Center 5.021 Remote File Inclusion via Proxy APIEPSS 0.5%