Falhas do tipo CWE-829

242 resultados

Inclusão de funcionalidade de fonte não confiável

A aplicação importa ou carrega código, bibliotecas ou plugins de uma fonte que não pode ser verificada ou controlada adequadamente. Um atacante pode interceptar, modificar ou substituir esse componente externo, injetando malware ou lógica maliciosa na aplicação. O risco é crítico porque o código não confiável executa com os mesmos privilégios da aplicação.

Exemplo

Um app Node.js que baixa um módulo npm sem verificar assinatura ou hash, ou um desktop app que carrega uma DLL de um diretório acessível a usuários locais. Se o atacante conseguir colocar uma versão comprometida antes do carregamento, o código malicioso roda dentro do processo.

Como mitigar

Implemente verificação de integridade (hash criptográfico, assinatura digital) para todo código externo antes de executar. Use repositórios oficiais, versione explicitamente as dependências, bloqueie carregamento dinâmico de paths não seguros e mantenha um inventário de componentes confiáveis. Isole e revise regularmente dependências críticas.

CVE-2026-55698HIGHpnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytesEPSS 0.3%CVE-2026-79721HIGHCode execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact toEPSS 0.3%CVE-2026-66843LOWhtml_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing untrusted content embeddingEPSS 0.3%CVE-2024-24821HIGHCode execution and possible privilege escalation via compromised InstalledVersions.php or installed.php in ComposerEPSS 0.3%CVE-2025-12509HIGHScripts for the module Global_Shipping executable on BRAIN2 ServerEPSS 0.3%CVE-2025-55305MEDIUMElectron is vulnerable to Code Injection via resource modificationEPSS 0.3%CVE-2025-0982CRITICALSandbox Escape in Google Cloud Application Integration's JavaScript Task (Rhino Engine)EPSS 0.3%CVE-2026-73367HIGHWordPress Easy Google Maps plugin < 1.14.2 - Remote File Inclusion vulnerabilityEPSS 0.2%CVE-2026-40903CRITICALGoshs - ArtiPACKED Vulnerability – GitHub Actions Credential PersistenceEPSS 0.2%CVE-2025-36852CRITICALBuild Cache Poisoning via Untrusted Pull RequestsEPSS 0.2%CVE-2025-55273MEDIUMHCL Aftermarket DPC is affected by Cross Domain Script Include vulnerabilityEPSS 0.2%CVE-2026-28135HIGHWordPress Royal Elementor Addons plugin <= 1.7.1052 - Other vulnerability Type vulnerabilityEPSS 0.2%CVE-2026-5843HIGHDocker Model Runner container-to-host code execution via MLX-LM model_file importlib loadingEPSS 0.2%CVE-2026-5817HIGHDocker Model Runner container-to-host code execution via unsandboxed trust_remote_code in Python inference backendsEPSS 0.2%CVE-2026-34442MEDIUMFreeScout: Host Header Injection Leading to External Resource Loading and Open Redirect in FreeScoutEPSS 0.2%CVE-2025-15612MEDIUMWazuh Provisioning Scripts / Build Infrastructure Improper Certificate Validation leading to MITM and RCEEPSS 0.2%CVE-2026-50562CRITICALFastGPT: Untrusted PR artifacts are pushed and deployed by privileged preview workflowsEPSS 0.2%CVE-2026-22283HIGHDell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Inclusion of Functionality from Untrusted Control Sphere vulnerability. AEPSS 0.2%CVE-2025-68162LOWIn JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configurationEPSS 0.2%CVE-2026-40156HIGHPraisonAI Affected by Implicit Execution of Arbitrary Code via Automatic `tools.py` LoadingEPSS 0.2%