Falhas do tipo CWE-829

242 resultados

Inclusão de funcionalidade de fonte não confiável

A aplicação importa ou carrega código, bibliotecas ou plugins de uma fonte que não pode ser verificada ou controlada adequadamente. Um atacante pode interceptar, modificar ou substituir esse componente externo, injetando malware ou lógica maliciosa na aplicação. O risco é crítico porque o código não confiável executa com os mesmos privilégios da aplicação.

Exemplo

Um app Node.js que baixa um módulo npm sem verificar assinatura ou hash, ou um desktop app que carrega uma DLL de um diretório acessível a usuários locais. Se o atacante conseguir colocar uma versão comprometida antes do carregamento, o código malicioso roda dentro do processo.

Como mitigar

Implemente verificação de integridade (hash criptográfico, assinatura digital) para todo código externo antes de executar. Use repositórios oficiais, versione explicitamente as dependências, bloqueie carregamento dinâmico de paths não seguros e mantenha um inventário de componentes confiáveis. Isole e revise regularmente dependências críticas.

CVE-2026-56447CRITICALMISP remote code execution via arbitrary rdkafka configuration pathEPSS 0.6%CVE-2026-93993HIGHMistral Vibe before 2.25.5 Remote Code Execution via git post-checkoutEPSS 0.6%CVE-2024-54663HIGHAn issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Inclusion (LFI) vulnerabEPSS 0.6%CVE-2024-43690HIGHInclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allow an attacker to perEPSS 0.6%CVE-2026-5241HIGHPolicy Bypass in LightGlue Nested Config Resolution in huggingface/transformersEPSS 0.6%CVE-2023-41267Apache HDFS Provider error message suggested installation of incorrect pip packageEPSS 0.6%CVE-2024-5693MEDIUMOffscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of saEPSS 0.6%CVE-2026-47398HIGHPraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334EPSS 0.6%CVE-2026-42510MEDIUMOpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.EPSS 0.6%CVE-2026-26974HIGHSylde has Improper Control of Generation of CodeEPSS 0.6%CVE-2024-45416HIGHThe HTTPD binary in multiple ZTE routers has a local file inclusion vulnerability in session_init function. The session -LUA- files are storEPSS 0.6%CVE-2020-36924MEDIUMSony BRAVIA Digital Signage 1.7.8 Unauthenticated Remote File InclusionEPSS 0.5%CVE-2022-31156MEDIUMGradle's dependency verification can ignore checksum verification when signature verification cannot be performedEPSS 0.5%CVE-2025-11023CRITICALLocal File Inclusion in ArkSigner's AcBakImzalaEPSS 0.5%CVE-2024-3043HIGHZigbee co-ordinator realignment packet may lead to denial of serviceEPSS 0.5%CVE-2026-46529HIGHPDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopenEPSS 0.5%CVE-2026-67623HIGHMistral Vibe < 2.23.3 Arbitrary Command Execution via git fsmonitor HookEPSS 0.5%CVE-2026-1699CRITICALIn the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_target trigger while chEPSS 0.5%CVE-2024-48336HIGHThe install() function of ProviderInstaller.java in Magisk App before canary version 27007 does not verify the GMS app before loading it, whEPSS 0.5%CVE-2020-36905MEDIUMFIBARO System Home Center 5.021 Remote File Inclusion via Proxy APIEPSS 0.5%