Fallos del tipo CWE-913

86 resultados

Controle inadequado de recursos de código gerenciado dinamicamente

É quando a aplicação carrega, executa ou modifica código dinamicamente (via eval, reflection, desserialização, plugins) sem validação ou controle suficiente. Um atacante pode injetar código malicioso que será executado com os mesmos privilégios da aplicação, contornando controles de segurança.

Ejemplo

Uma aplicação Java que desserializa dados untrusted diretamente com ObjectInputStream permite ao atacante executar código arbitrário; ou um sistema que usa eval() em strings enviadas pelo usuário sem validação prévia.

Cómo mitigar

Nunca use eval() ou equivalentes com entrada untrusted. Se precisar executar código dinamicamente, use listas brancas estritas, sandboxes de execução ou frameworks que isolem o código dinâmico. Valide e sanitize serialização com bibliotecas seguras (ex: Java com Deserialization filters).

CVE-2025-6107LOWcomfyanonymous comfyui utils.py set_attr dynamically-determined object attributesEPSS 0.4%CVE-2025-13426HIGHImproper Sandboxing in Google Apigee's JavaCallout Policy Allows for Remote Code ExecutionEPSS 0.4%CVE-2026-71470CRITICALAcm-search-v2-rhel9: search-v2-operator: search cr imageoverride/arguments/envvar flow unsanitized into pods running impersonating saEPSS 0.4%CVE-2025-14085MEDIUMyoulaitech youlai-mall orders improper control of dynamically-identified variablesEPSS 0.4%CVE-2023-4041CRITICALSecond Stage Gecko Bootloader GBL Parser Buffer Overrun VulnerabilityEPSS 0.4%CVE-2026-73226HIGHElecterm WebSocket `upgrade-func` and `fs` handlers allow arbitrary method/function invocation due to missing method-name allowlistEPSS 0.4%CVE-2026-47137CRITICALvm2: GHSA-8hg8-63c5-gwmx patch bypass: nesting:true without explicit require still allows full RCEEPSS 0.4%CVE-2024-5401MEDIUMImproper control of dynamically-managed code resources vulnerability in WebAPI component in Synology DiskStation Manager (DSM) before 7.1.1-EPSS 0.4%CVE-2026-59283CRITICALSpring Framework Safety Guard Bypass via SpEL Expression CompilationEPSS 0.4%CVE-2026-92953CRITICALvm2 3.11.0 through 3.11.7 Prototype Pollution via TypedArrayEPSS 0.3%CVE-2025-46675LOWIn NASA CryptoLib before 1.3.2, the key state is not checked before use, potentially leading to spacecraft hijacking.EPSS 0.3%CVE-2026-92217MEDIUMa2ui-project a2ui Message Parsing message-processor.ts processMessages dynamically-determined object attributesEPSS 0.3%CVE-2021-42809MEDIUMThe Sentinel Protection Installer 7.7.0 does not properly restrict loading Dynamic Link LibraryEPSS 0.3%CVE-2024-2537MEDIUMElectron Code Injection in Logi Tune macOS ApplicationEPSS 0.3%CVE-2025-14695MEDIUMSamuNatsu HaloBot Inter-plugin API index.js html_renderer dynamically-managed code resourcesEPSS 0.3%CVE-2026-84430MEDIUMgouguoa edit_personal Endpoint Index.php update dynamically-determined object attributesEPSS 0.2%CVE-2025-6705HIGHA vulnerability in the Eclipse Open VSX Registry’s automated publishing system could have allowed unauthorized uploads of extensions. SpecifEPSS 0.2%CVE-2026-5251MEDIUMz-9527 admin User Update Endpoint user.js dynamically-determined object attributesEPSS 0.2%CVE-2026-5248MEDIUMgougucms User Registration Login.php reg_submit dynamically-determined object attributesEPSS 0.2%CVE-2026-85408MEDIUMEleveo Quality Management Conversation events dynamically-determined object attributesEPSS 0.2%