Falhas do tipo CWE-829

242 resultados

Inclusão de funcionalidade de fonte não confiável

A aplicação importa ou carrega código, bibliotecas ou plugins de uma fonte que não pode ser verificada ou controlada adequadamente. Um atacante pode interceptar, modificar ou substituir esse componente externo, injetando malware ou lógica maliciosa na aplicação. O risco é crítico porque o código não confiável executa com os mesmos privilégios da aplicação.

Exemplo

Um app Node.js que baixa um módulo npm sem verificar assinatura ou hash, ou um desktop app que carrega uma DLL de um diretório acessível a usuários locais. Se o atacante conseguir colocar uma versão comprometida antes do carregamento, o código malicioso roda dentro do processo.

Como mitigar

Implemente verificação de integridade (hash criptográfico, assinatura digital) para todo código externo antes de executar. Use repositórios oficiais, versione explicitamente as dependências, bloqueie carregamento dinâmico de paths não seguros e mantenha um inventário de componentes confiáveis. Isole e revise regularmente dependências críticas.

CVE-2026-44688HIGHIn Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context withEPSS 0.5%CVE-2026-46580HIGHIn Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded andEPSS 0.5%CVE-2025-24796MEDIUMRemote Code Execution within Collabora Online jail with Macros EnabledEPSS 0.5%CVE-2026-86169HIGHAxolotl before 0.19.0 Remote Code Execution via Multipack PatchingEPSS 0.5%CVE-2026-15560HIGHOpenjdk-orb: unauthed class loading via iiop in eapEPSS 0.5%CVE-2025-61592HIGHCursor CLI: Arbitrary Code Execution Possible through Permissive CLI ConfigEPSS 0.5%CVE-2026-76139HIGHAcm-operator-bundle: acm-operator-bundle: bundle build execs unpinned stolostron/release@master with full build credentialsEPSS 0.4%CVE-2022-41709HIGHMarkdownify version 1.4.1 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdoEPSS 0.4%CVE-2026-6859HIGHInstructlab: instructlab: arbitrary code execution due to hardcoded `trust_remote_code=true`EPSS 0.4%CVE-2026-66902CRITICALGoogle::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system callEPSS 0.4%CVE-2026-47292HIGHVisual Studio Code MSSQL Extension Remote Code Execution VulnerabilityEPSS 0.4%CVE-2019-10240Eclipse hawkBit versions prior to 0.3.0M2 resolved Maven build artifacts for the Vaadin based UI over HTTP instead of HTTPS. Any of these deEPSS 0.4%CVE-2019-10248Eclipse Vorto versions prior to 0.11 resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS. Any of these dependentEPSS 0.4%CVE-2022-31021LOWUnlinkability broken in ursa when verifiers use malicious keysEPSS 0.4%CVE-2025-36727HIGHSimpleHelp Inclusion of functionality from untrusted control sphereEPSS 0.4%CVE-2026-53810HIGHOpenClaw < 2026.5.18 - Arbitrary Code Execution via Unscanned Marketplace Runtime Extension MetadataEPSS 0.4%CVE-2026-18252HIGHInclusion of Functionality from Untrusted Control Sphere in GitLabEPSS 0.4%CVE-2026-54916HIGHNetBox Device Type Library: Module Shadowing Bypass of prior pickle fix - RCE via missing `tests/__init__.py` + SSRF via unfixed `NETBOX_DT_LIBRARY_URL` → Cloud Metadata credential theftEPSS 0.4%CVE-2026-44691HIGHIn Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be EPSS 0.4%CVE-2026-27941CRITICALOpenLIT Vulnerable to Remote Code Execution and Secret Exposure via Misuse of `pull_request_target` in GitHub Actions WorkflowsEPSS 0.4%