Falhas do tipo CWE-829

242 resultados

Inclusão de funcionalidade de fonte não confiável

A aplicação importa ou carrega código, bibliotecas ou plugins de uma fonte que não pode ser verificada ou controlada adequadamente. Um atacante pode interceptar, modificar ou substituir esse componente externo, injetando malware ou lógica maliciosa na aplicação. O risco é crítico porque o código não confiável executa com os mesmos privilégios da aplicação.

Exemplo

Um app Node.js que baixa um módulo npm sem verificar assinatura ou hash, ou um desktop app que carrega uma DLL de um diretório acessível a usuários locais. Se o atacante conseguir colocar uma versão comprometida antes do carregamento, o código malicioso roda dentro do processo.

Como mitigar

Implemente verificação de integridade (hash criptográfico, assinatura digital) para todo código externo antes de executar. Use repositórios oficiais, versione explicitamente as dependências, bloqueie carregamento dinâmico de paths não seguros e mantenha um inventário de componentes confiáveis. Isole e revise regularmente dependências críticas.

CVE-2026-54981HIGHVisual Studio Code Python Extension Security Feature Bypass VulnerabilityEPSS 0.4%CVE-2023-31168MEDIUM Inclusion of Functionality from Untrusted Control SphereEPSS 0.4%CVE-2026-44484CRITICALCompromise of PyTorch Lightning PyPi Package VersionsEPSS 0.4%CVE-2024-32011HIGHA vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to run EPSS 0.4%CVE-2026-43571HIGHOpenClaw < 2026.4.10 - Untrusted Workspace Plugin Shadow Resolution in Channel SetupEPSS 0.4%CVE-2022-46302HIGHRemote Code Execution with Root Privileges via Broad Apache PermissionsEPSS 0.4%CVE-2026-43569HIGHOpenClaw < 2026.4.9 - Untrusted Provider Plugin Auto-enablement via Workspace Provider AuthEPSS 0.4%CVE-2026-8879HIGHCVE-2026-8879EPSS 0.4%CVE-2026-28372HIGHtelnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added EPSS 0.4%CVE-2026-45272CRITICALMyBooks: Remote Code Execution via SOCIAL_AUTH Key Name Injection in Python Config FileEPSS 0.4%CVE-2026-26862HIGHCleverTap Web SDK version 1.15.2 and earlier is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage in the Visual BuilEPSS 0.4%CVE-2025-59828HIGHClaude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn VersionsEPSS 0.4%CVE-2026-43944CRITICALelecterm: dangerous code can be run through links or command lineEPSS 0.4%CVE-2026-18408HIGHPostgreSQL psql \unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql clientEPSS 0.4%CVE-2025-70046CRITICALAn issue pertaining to CWE-829: Inclusion of Functionality from Untrusted Control Sphere was discovered in Miazzy oa-front-service master.EPSS 0.4%CVE-2026-6464HIGHPostgreSQL psql COPY FROM STDIN early failure processes data lines as psql commandsEPSS 0.4%CVE-2025-67842MEDIUMThe Static Asset API in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HTML via the subdomainEPSS 0.4%CVE-2026-54752CRITICALNetBox Device Type Library: Insecure Pickle Deserialization in Test Suite Allows Remote Code Execution via Malicious Pull RequestEPSS 0.4%CVE-2026-15519LOWusestrix PyPI system_prompt.jinja inclusion of functionality from untrusted control sphereEPSS 0.3%CVE-2023-31170MEDIUM Inclusion of Functionality from Untrusted Control SphereEPSS 0.3%