Fallos del tipo CWE-829

242 resultados

Inclusão de funcionalidade de fonte não confiável

Ocorre quando uma aplicação carrega ou executa código, bibliotecas ou componentes originários de uma fonte não verificada ou controlada por terceiros. O risco é alto porque o código malicioso ou comprometido executa com os mesmos privilégios da aplicação, permitindo roubo de dados, injeção de código ou compromisso total do sistema.

Ejemplo

Um aplicativo web busca um script JavaScript de um CDN externo sem validar assinatura criptográfica. Se o CDN for comprometido ou o tráfego interceptado, o atacante injeta código que rouba credenciais dos usuários. Outro caso: uma dependência npm instalada automaticamente é atualizada e passa a conter malware, afetando todos os projetos que a consomem.

Cómo mitigar

Valide a origem e integridade de componentes: use subresource integrity (SRI) para scripts externos, verifique assinaturas digitais de pacotes, mantenha dependências em repositório privado controlado, e audite regularmente bibliotecas críticas com ferramentas como npm audit ou SBOM. Implemente listas de permissão (whitelist) de fontes confiáveis e isole a execução quando possível.

CVE-2026-44688HIGHIn Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context withEPSS 0.5%CVE-2026-46580HIGHIn Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded andEPSS 0.5%CVE-2025-24796MEDIUMRemote Code Execution within Collabora Online jail with Macros EnabledEPSS 0.5%CVE-2026-86169HIGHAxolotl before 0.19.0 Remote Code Execution via Multipack PatchingEPSS 0.5%CVE-2026-15560HIGHOpenjdk-orb: unauthed class loading via iiop in eapEPSS 0.5%CVE-2025-61592HIGHCursor CLI: Arbitrary Code Execution Possible through Permissive CLI ConfigEPSS 0.5%CVE-2026-76139HIGHAcm-operator-bundle: acm-operator-bundle: bundle build execs unpinned stolostron/release@master with full build credentialsEPSS 0.4%CVE-2022-41709HIGHMarkdownify version 1.4.1 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdoEPSS 0.4%CVE-2026-6859HIGHInstructlab: instructlab: arbitrary code execution due to hardcoded `trust_remote_code=true`EPSS 0.4%CVE-2026-66902CRITICALGoogle::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system callEPSS 0.4%CVE-2026-47292HIGHVisual Studio Code MSSQL Extension Remote Code Execution VulnerabilityEPSS 0.4%CVE-2019-10240Eclipse hawkBit versions prior to 0.3.0M2 resolved Maven build artifacts for the Vaadin based UI over HTTP instead of HTTPS. Any of these deEPSS 0.4%CVE-2019-10248Eclipse Vorto versions prior to 0.11 resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS. Any of these dependentEPSS 0.4%CVE-2022-31021LOWUnlinkability broken in ursa when verifiers use malicious keysEPSS 0.4%CVE-2025-36727HIGHSimpleHelp Inclusion of functionality from untrusted control sphereEPSS 0.4%CVE-2026-53810HIGHOpenClaw < 2026.5.18 - Arbitrary Code Execution via Unscanned Marketplace Runtime Extension MetadataEPSS 0.4%CVE-2026-18252HIGHInclusion of Functionality from Untrusted Control Sphere in GitLabEPSS 0.4%CVE-2026-54916HIGHNetBox Device Type Library: Module Shadowing Bypass of prior pickle fix - RCE via missing `tests/__init__.py` + SSRF via unfixed `NETBOX_DT_LIBRARY_URL` → Cloud Metadata credential theftEPSS 0.4%CVE-2026-44691HIGHIn Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be EPSS 0.4%CVE-2026-27941CRITICALOpenLIT Vulnerable to Remote Code Execution and Secret Exposure via Misuse of `pull_request_target` in GitHub Actions WorkflowsEPSS 0.4%