Falhas do tipo CWE-829

242 resultados

Inclusão de funcionalidade de fonte não confiável

A aplicação importa ou carrega código, bibliotecas ou plugins de uma fonte que não pode ser verificada ou controlada adequadamente. Um atacante pode interceptar, modificar ou substituir esse componente externo, injetando malware ou lógica maliciosa na aplicação. O risco é crítico porque o código não confiável executa com os mesmos privilégios da aplicação.

Exemplo

Um app Node.js que baixa um módulo npm sem verificar assinatura ou hash, ou um desktop app que carrega uma DLL de um diretório acessível a usuários locais. Se o atacante conseguir colocar uma versão comprometida antes do carregamento, o código malicioso roda dentro do processo.

Como mitigar

Implemente verificação de integridade (hash criptográfico, assinatura digital) para todo código externo antes de executar. Use repositórios oficiais, versione explicitamente as dependências, bloqueie carregamento dinâmico de paths não seguros e mantenha um inventário de componentes confiáveis. Isole e revise regularmente dependências críticas.

CVE-2026-24226MEDIUMNVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exploEPSS 0.2%CVE-2026-22865HIGHGradle's failure to disable repositories failing to answer can expose builds to malicious artifactsEPSS 0.2%CVE-2025-33205HIGHNVIDIA NeMo framework contains a vulnerability in a predefined variable, where an attacker could cause inclusion of functionality from an unEPSS 0.2%CVE-2026-55522HIGHPraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe codeEPSS 0.2%CVE-2025-49809HIGHmtr through 0.95, in certain privileged contexts, mishandles execution of a program specified by the MTR_PACKET environment variable. NOTE: EPSS 0.2%CVE-2025-53841HIGHThe GC-AGENTS-SERVICE running as part of Akamai´s Guardicore Platform Agent for Windows versions prior to v49.20.1, v50.15.0, v51.12.0, v52.EPSS 0.2%CVE-2026-45184MEDIUMKdenlive before 26.04.1 allows dangerous proxy parameters when an attacker-controlled project file is used.EPSS 0.1%CVE-2024-45482HIGHPrivilege escalation in B&R APROLEPSS 0.1%CVE-2026-73073HIGHVim: Arbitrary Ex Command Execution in C Omni-CompletionEPSS 0.1%CVE-2026-44312MEDIUMcss_parser allows to MITM included https css urlsEPSS 0.1%CVE-2026-48124HIGHCursor Desktop sandbox escape via Claude hook configurationEPSS 0.1%CVE-2026-82525MEDIUMExterro FTK Imager < 8.3 XXE via Report.xml XSLT ProcessingEPSS 0.1%CVE-2025-62186MEDIUMAnkitects Anki before 25.02.5 allows a crafted shared deck on Windows to execute arbitrary commands when playing audio because of URL schemeEPSS 0.1%CVE-2026-6357MEDIUMpip self-update functionality can import newly installed modules after wheel installationEPSS 0.1%CVE-2026-44995MEDIUMOpenClaw < 2026.4.20 - Arbitrary Code Execution via MCP stdio Environment VariablesEPSS 0.1%CVE-2026-1628MEDIUMMattermost allows external websites to open within the app, exposing preload functionality to non-trusted sites.EPSS 0.1%CVE-2025-69257MEDIUMtheshit vulnerable to unsafe loading of user-owned Python rules when running as root.EPSS 0.1%CVE-2026-41336HIGHOpenClaw < 2026.3.31 - Arbitrary Hook Code Execution via OPENCLAW_BUNDLED_HOOKS_DIR Environment Variable OverrideEPSS 0.1%CVE-2026-8428HIGHCSRF token is not validated in the core CMS update controller for Concrete CMS 9.5.0 and belowEPSS 0.1%CVE-2026-47781HIGHpdm: Project-Controlled `.pdm-plugins` Content Executes Before CLI ParsingEPSS 0.1%