Weaknesses of type CWE-829

210 results

Inclusão de funcionalidade de esfera de controle não confiável

Ocorre quando o software importa, carrega ou executa código, bibliotecas ou componentes originários de uma fonte não confiável ou não verificada. O atacante consegue injetar funcionalidade maliciosa que rodará com os mesmos privilégios da aplicação, comprometendo a integridade e segurança do sistema.

Example

Uma aplicação web baixa dinamicamente um plugin ou módulo de um servidor externo sem validar assinatura criptográfica ou integridade. Um atacante intercepta ou compromete o servidor de origem e substitui o arquivo legítimo por uma versão maliciosa; a aplicação carrega e executa o código comprometido automaticamente.

How to mitigate

Valide sempre a origem, autenticidade e integridade de componentes antes de carregá-los: use assinatura digital criptográfica, checksums verificados, HTTPS com pinning de certificado e, quando possível, evite carregamento dinâmico. Mantenha inventário atualizado de dependências e aplique patches regularmente.

CVE-2026-42510MEDIUMOpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.EPSS 0.5%CVE-2026-5241HIGHPolicy Bypass in LightGlue Nested Config Resolution in huggingface/transformersEPSS 0.5%CVE-2026-26974HIGHSylde has Improper Control of Generation of CodeEPSS 0.5%CVE-2025-11023CRITICALLocal File Inclusion in ArkSigner's AcBakImzalaEPSS 0.5%CVE-2024-3043HIGHZigbee co-ordinator realignment packet may lead to denial of serviceEPSS 0.5%CVE-2026-46529HIGHPDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopenEPSS 0.5%CVE-2026-67623HIGHMistral Vibe < 2.23.3 Arbitrary Command Execution via git fsmonitor HookEPSS 0.5%CVE-2024-48336HIGHThe install() function of ProviderInstaller.java in Magisk App before canary version 27007 does not verify the GMS app before loading it, whEPSS 0.5%CVE-2022-31156MEDIUMGradle's dependency verification can ignore checksum verification when signature verification cannot be performedEPSS 0.5%CVE-2026-44688HIGHIn Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context withEPSS 0.5%CVE-2026-46580HIGHIn Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded andEPSS 0.5%CVE-2026-1699CRITICALIn the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_target trigger while chEPSS 0.5%CVE-2025-24796MEDIUMRemote Code Execution within Collabora Online jail with Macros EnabledEPSS 0.5%CVE-2020-36924MEDIUMSony BRAVIA Digital Signage 1.7.8 Unauthenticated Remote File InclusionEPSS 0.5%CVE-2023-41267Apache HDFS Provider error message suggested installation of incorrect pip packageEPSS 0.5%CVE-2020-36905MEDIUMFIBARO System Home Center 5.021 Remote File Inclusion via Proxy APIEPSS 0.5%CVE-2022-41709HIGHMarkdownify version 1.4.1 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdoEPSS 0.4%CVE-2026-66902CRITICALGoogle::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system callEPSS 0.4%CVE-2026-47292HIGHVisual Studio Code MSSQL Extension Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-40501HIGHCherry Studio RCE via SearchService nodeIntegration MisconfigurationEPSS 0.4%