CWE-829— Inclusion of Functionality from Untrusted Control Sphere
The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.— MITRE CWE catalog
304 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-829page 6 of 7
- CVE-2026-43999CRITICALCVSS 9.9EG 9.92026-05-13
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, NodeVM's builtin allowlist can be bypassed when the module builtin is allowed (including via the '*' wildcard). The module builtin exposes Node's Module._load(), which loads an…
- CVE-2026-44312MEDIUMCVSS 5.8EG 5.82026-05-14
css_parser is a Ruby CSS parser. Prior to 2.1.0 and 1.22.0, the CSS Parser gem does not validate HTTPS connections, allowing a Man-in-the-Middle (MITM) attacker to inject or modify CSS content when stylesheets are loaded via HTTPS. The con…
- CVE-2026-44336CRITICALCVSS 9.6EG 9.62026-05-08
PraisonAI is a multi-agent teams system. Prior to version 4.6.34, PraisonAI's MCP (Model Context Protocol) server (praisonai mcp serve) registers four file-handling tools by default — praisonai.rules.create, praisonai.rules.show, praison…
- CVE-2026-44358HIGHCVSS 8.2EG 8.22026-05-28
Espressif Shared GitHub DangerJS is a reusable GitHub Action CI DangerJS workflow for Espressif GitHub projects. Prior to 1.0.1, the action's entrypoint.sh invoked DangerJS from the caller's workspace after copying the fork's checkout into…
- CVE-2026-44359CRITICALCVSS 10.0EG 10.02026-07-19
Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow is triggered by pull_request_target and multiple jobs check out the attacker's fork code a…
- CVE-2026-44484CRITICALCVSS 9.8EG 9.82026-05-14
PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introduced functionality consistent with a credential harvesting mechanism.
- CVE-2026-44688HIGHCVSS 8.8EG 8.82026-06-18
In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context without distinguishing them from system instructions. An attacker could craft a malicious repository wi…
- CVE-2026-44691HIGHCVSS 8.8EG 8.82026-06-18
In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be executed without requiring workspace trust. An attacker could craft a malicious repository that, wh…
- CVE-2026-44995HIGHCVSS 7.3EG 7.32026-05-11
OpenClaw before 2026.4.20 contains an improper environment variable validation vulnerability in MCP stdio server configuration that allows attackers to execute arbitrary code. Malicious workspace configurations can pass dangerous startup v…
- CVE-2026-45184MEDIUMCVSS 6.5EG 6.52026-05-09
Kdenlive before 26.04.1 allows dangerous proxy parameters when an attacker-controlled project file is used.
- CVE-2026-45711MEDIUMCVSS 5.9EG 5.92026-05-19
Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the mailpit dump --http <base-url> <out-dir> sub-command downloads every message from a remote Mailpit instance and writes each one as <id>.eml inside the us…
- CVE-2026-46529HIGHCVSS 7.8EG 7.82026-06-10
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code executio…
- CVE-2026-46580HIGHCVSS 8.8EG 8.82026-06-18
In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could override or extend the AI agent's system prompts. An attacker could craft a malicious reposi…
- CVE-2026-47172CRITICALCVSS 9.5EG 9.52026-06-11
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, the repository has a privileged deploy workflow that runs after the unprivileged build workflow completes. The build workflo…
- CVE-2026-47174CRITICALCVSS 9.5EG 9.52026-06-11
In Duck Site before version 1.0.1, the repository has a deploy workflow that runs after the build workflow completes. The build workflow runs on pull requests, while the deploy workflow runs with package-write permissions and deployment se…
- CVE-2026-47292HIGHCVSS 7.8EG 7.82026-06-09
Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
- CVE-2026-47398HIGHCVSS 8.1EG 8.12026-05-29
PraisonAI is a multi-agent teams system. The v4.6.32 chokepoint refactor (which patched CVE-2026-44334 / GHSA-xcmw-grxf-wjhj) added the PRAISONAI_ALLOW_LOCAL_TOOLS env-var gate to the tool_override.py sinks. However, two additional spec.lo…
- CVE-2026-48124HIGHCVSS 8.5EG 8.52026-06-15
Cursor is a code editor built for programming with AI. In versions prior to 3.0.0, the Cursor Desktop could execute workspace-defined Claude hook commands from .claude/settings.local.json without dedicated user approval. A malicious worksp…
- CVE-2026-50195CRITICALCVSS 9.9EG 9.92026-06-19
containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the CRI checkpoint import process where it fails to validate the image references specified within a checkpoint image's con…
- CVE-2026-50562CRITICALCVSS 9.3EG 9.32026-07-15
FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, artifacts built from untrusted pull request code in .github/workflows/preview-docs-build.yml and .github/workflows/previe…
- CVE-2026-5241CRITICALCVSS 9.6EG 9.62026-06-03
A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_…
- CVE-2026-52858HIGHCVSS 7.8EG 7.82026-06-11
Vim is an open source, command line text editor. Prior to version 9.2.0561, the Python omni-completion script in python3complete.vim for Vim with the +python3 interpreter enabled (and the legacy pythoncomplete.vim for builds with the +pyth…
- CVE-2026-53810HIGHCVSS 8.8EG 8.82026-06-11
OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can redirect loading toward unscanned package payloads. Attackers with trusted operator access can manipulate extension metadata…
- CVE-2026-54325MEDIUMCVSS 4.4EG 4.42026-06-17
Pi is a minimal terminal coding harness. Pi before 0.79.0 loaded project-local configuration and resources from a repository's .pi directory without first asking the user to trust that repository. This included project-local extensions, wh…
- CVE-2026-55487HIGHCVSS 8.8EG 8.82026-06-25
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, the generic peer-suffix normalizer also stripped parenthesized text from git, URL, tarball, file, and other opaque locators. Approval for one source string could therefore authorize a…
- CVE-2026-55697HIGHCVSS 8.8EG 8.82026-06-25
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can install configDependencies declared in pnpm-workspace.yaml before command dispatch. Before the patch, a repository could declare pacquet or @pnpm/pacquet as a config dependen…
- CVE-2026-55698HIGHCVSS 8.8EG 8.82026-06-25
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persist package-manager bootstrap metadata in the first YAML document of pnpm-lock.yaml. Before the patch, direct pnpm execution trusted an already resolved packageManagerDep…
- CVE-2026-56447HIGHCVSS 7.2EG 7.22026-06-22
MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path. MISP subsequently parsed the referenced INI file and passed its options to rdkafka. A crafted attacker-controlled con…
- CVE-2026-57102HIGHCVSS 8.8EG 8.82026-07-14
Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-57860HIGHCVSS 7.8EG 7.82026-07-17
ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI, automatically loads and executes the MCP servers defined in a repository's .mcp.json file on startup without user confirmation. A malicious repository can supply a crafted .mcp.…
- CVE-2026-58116CRITICALCVSS 8.8EG 9.82026-06-30
LLaMA-Factory through 0.9.5 contains a remote code execution vulnerability that allows attackers with WebUI access to execute arbitrary Python code by supplying a malicious model path in the Chat or Training interfaces. The application pas…
- CVE-2026-5817HIGHCVSS 8.6EG 8.62026-05-26
The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing. This causes transformers.AutoTokenizer.from_pretrained() to import and…
- CVE-2026-5843HIGHCVSS 8.6EG 8.62026-05-26
The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the model_file configuration field in config.json. When a model…
- CVE-2026-59831MEDIUMCVSS 4.4EG 4.42026-07-09
GitHub CLI (gh) is GitHub’s official command line tool. From 2.10.0 through 2.95.0, connecting to a malicious Codespace with gh codespace jupyter can allow command execution because the command opens a JupyterLab URL supplied by a proces…
- CVE-2026-59864CRITICALCVSS 9.3EG 9.32026-07-16
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota plugin add` and `kiota plugin generate` (with `-t APIPlugin`) emitted attacker-controlled static_template.file values from x-ai-adaptive-card and x-ai-capabiliti…
- CVE-2026-59865CRITICALCVSS 9.3EG 9.32026-07-16
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota info` read x-ms-kiota-info.languagesInformation.<language>.dependencyInstallCommand plus dependency name and version values from an OpenAPI description and prese…
- CVE-2026-59867HIGHCVSS 7.1EG 7.12026-07-16
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota resolved OpenAPI $ref values by fetching remote http(s) URLs and reading local absolute or out-of-tree file paths, allowing `kiota generate` on an attacker-contro…
- CVE-2026-62222HIGHCVSS 7.8EG 7.82026-07-17
OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted workspace plugins. Attackers with lower-trust caller access or control over configured input paths can execute or persist actions be…
- CVE-2026-6357MEDIUMCVSS 5.3EG 5.32026-04-27
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip…
- CVE-2026-64804HIGHCVSS 8.4EG 8.42026-07-23
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling
- CVE-2026-64805HIGHCVSS 8.4EG 8.42026-07-23
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling
- CVE-2026-64806HIGHCVSS 8.4EG 8.42026-07-23
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter
- CVE-2026-64807HIGHCVSS 7.8EG 7.82026-07-23
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration
- CVE-2026-64808HIGHCVSS 8.4EG 8.42026-07-23
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling
- CVE-2026-64809HIGHCVSS 8.4EG 8.42026-07-23
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter
- CVE-2026-64811HIGHCVSS 7.8EG 7.82026-07-23
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration
- CVE-2026-6482HIGHCVSS 7.8EG 7.82026-04-17
The Rapid7 Insight Agent (versions > 4.1.0.2) is vulnerable to a local privilege escalation attack that allows users to gain SYSTEM level control of a Windows host. Upon startup the agent service attempts to load an OpenSSL configuration …
- CVE-2026-65908HIGHCVSS 8.6EG 8.62026-07-23
In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open
- CVE-2026-66141HIGHCVSS 7.4EG 7.42026-07-24
Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.
- CVE-2026-6859HIGHCVSS 8.8EG 8.82026-04-22
A flaw was found in InstructLab. The `linux_train.py` script hardcodes `trust_remote_code=True` when loading models from HuggingFace. This allows a remote attacker to achieve arbitrary Python code execution by convincing a user to run `ila…
Map vulnerabilities like CWE-829 to your infrastructure
EchelonGraph correlates every CVE — across CWE-829 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →