Falhas do tipo CWE-829

242 resultados

Inclusão de funcionalidade de fonte não confiável

A aplicação importa ou carrega código, bibliotecas ou plugins de uma fonte que não pode ser verificada ou controlada adequadamente. Um atacante pode interceptar, modificar ou substituir esse componente externo, injetando malware ou lógica maliciosa na aplicação. O risco é crítico porque o código não confiável executa com os mesmos privilégios da aplicação.

Exemplo

Um app Node.js que baixa um módulo npm sem verificar assinatura ou hash, ou um desktop app que carrega uma DLL de um diretório acessível a usuários locais. Se o atacante conseguir colocar uma versão comprometida antes do carregamento, o código malicioso roda dentro do processo.

Como mitigar

Implemente verificação de integridade (hash criptográfico, assinatura digital) para todo código externo antes de executar. Use repositórios oficiais, versione explicitamente as dependências, bloqueie carregamento dinâmico de paths não seguros e mantenha um inventário de componentes confiáveis. Isole e revise regularmente dependências críticas.

CVE-2025-70974CRITICALFastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a JavaEPSS 0.8%CVE-2025-68924HIGHIn Umbraco UmbracoForms through 8.13.16, an authenticated attacker can supply a malicious WSDL (aka Webservice) URL as a data source for remEPSS 0.8%CVE-2025-62726HIGHn8n Vulnerable to Remote Code Execution via Git Node Pre-Commit HookEPSS 0.8%CVE-2025-34060CRITICALMonero Forum Remote Code Execution via Arbitrary File Read and Cookie ForgeryEPSS 0.7%CVE-2023-0625HIGHDocker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelogEPSS 0.7%CVE-2025-8714HIGHPostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql clientEPSS 0.7%CVE-2022-24119CRITICALCertain General Electric Renewable Energy products have a hidden feature for unauthenticated remote access to the device configuration shellEPSS 0.7%CVE-2023-36609HIGH The affected TBox RTUs run OpenVPN with root privileges and can run user defined configuration scripts. An attacker could set up a local OpEPSS 0.7%CVE-2022-22246HIGHJunos OS: PHP file inclusion vulnerability in J-WebEPSS 0.7%CVE-2025-66022CRITICALFACTION Unauthenticated Custom Extension Upload leads to RCEEPSS 0.7%CVE-2024-30092HIGHWindows Hyper-V Remote Code Execution VulnerabilityEPSS 0.7%CVE-2025-65964CRITICALn8n Vulnerable to Remote Code Execution via Git Node Custom Pre-Commit HookEPSS 0.7%CVE-2025-27668CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Arbitrary Content Inclusion via IfrEPSS 0.7%CVE-2019-10249All Xtext & Xtend versions prior to 2.18.0 were built using HTTP instead of HTTPS file transfer and thus the built artifacts may have been cEPSS 0.7%CVE-2025-27510CRITICALRCE in the package conda-forge-metadataEPSS 0.6%CVE-2022-41216HIGHCloudflow - Local File Inclusion VulnerabilityEPSS 0.6%CVE-2024-28184HIGHWeasyPrint allows the attachment of arbitrary files and URLs to a PDFEPSS 0.6%CVE-2026-44336CRITICALPraisonAI MCP `tools/call` path-traversal and RCE via Python `.pth` injectionEPSS 0.6%CVE-2023-45798HIGHYettiesoft VestCert Remote Code Execution VulnerabilityEPSS 0.6%CVE-2023-4591HIGHInclusion of Functionality from Untrusted Control Sphere in WPN-XM ServerstackEPSS 0.6%