CWE-829— Inclusion of Functionality from Untrusted Control Sphere
The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.— MITRE CWE catalog
338 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-829page 7 of 7
- CVE-2026-59865CRITICALCVSS 9.3EG 9.32026-07-16
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota info` read x-ms-kiota-info.languagesInformation.<language>.dependencyInstallCommand plus dependency name and version values from an OpenAPI descriptio…
- CVE-2026-59867HIGHCVSS 7.1EG 7.12026-07-16
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota resolved OpenAPI $ref values by fetching remote http(s) URLs and reading local absolute or out-of-tree file paths, allowing `kiota generate` on an atta…
- CVE-2026-62222HIGHCVSS 7.8EG 7.82026-07-17
OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted workspace plugins. Attackers with lower-trust caller access or control over configured input paths can execute or persist actions be…
- CVE-2026-62680HIGHCVSS 7.1EG 7.12026-08-19
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.22.0, Orval resolves remote and local external $ref values without an allowlist or confinement to the input directory. Pro…
- CVE-2026-62902MEDIUMCVSS 6.5EG 6.52026-08-11
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
- CVE-2026-6357MEDIUMCVSS 5.3EG 5.32026-04-27
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules names. These module imports were intentionally deferred to increase startup time of the pip…
- CVE-2026-6464HIGHCVSS 8.1EG 8.12026-08-13
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indi…
- CVE-2026-64804HIGHCVSS 8.4EG 8.42026-07-23
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling
- CVE-2026-64805HIGHCVSS 8.4EG 8.42026-07-23
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling
- CVE-2026-64806HIGHCVSS 8.4EG 8.42026-07-23
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter
- CVE-2026-64807HIGHCVSS 7.8EG 7.82026-07-23
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration
- CVE-2026-64808HIGHCVSS 8.4EG 8.42026-07-23
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling
- CVE-2026-64809HIGHCVSS 8.4EG 8.42026-07-23
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter
- CVE-2026-64811HIGHCVSS 7.8EG 7.82026-07-23
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration
- CVE-2026-6482HIGHCVSS 7.8EG 7.82026-04-17
The Rapid7 Insight Agent (versions > 4.1.0.2) is vulnerable to a local privilege escalation attack that allows users to gain SYSTEM level control of a Windows host. Upon startup the agent service attempts to load an OpenSSL configuration …
- CVE-2026-65908HIGHCVSS 8.6EG 8.62026-07-23
In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open
- CVE-2026-66141HIGHCVSS 7.8EG 7.82026-07-24
Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.
- CVE-2026-66843MEDIUMCVSS 6.1EG 6.12026-08-06
Inclusion of Functionality from Untrusted Control Sphere vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to load a document of their choosing into a trusted page via the data attribute of an <object>…
- CVE-2026-66902CRITICALCVSS 9.8EG 9.82026-08-04
Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call. The Pluggable subclass reads credential_source.executable.command from the credentials JSON and runs it as …
- CVE-2026-67623HIGHCVSS 8.8EG 8.82026-08-05
Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands by embedding a malicious core.fsmonitor hook in a repository's .git/config file, which is triggered when vibe inv…
- CVE-2026-6859HIGHCVSS 8.8EG 8.82026-04-22
A flaw was found in InstructLab. The `linux_train.py` script hardcodes `trust_remote_code=True` when loading models from HuggingFace. This allows a remote attacker to achieve arbitrary Python code execution by convincing a user to run `ila…
- CVE-2026-71471CRITICALCVSS 9.0EG 9.02026-08-12
A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the `Collector.ImageOverride` field…
- CVE-2026-73073HIGHCVSS 7.1EG 7.12026-08-18
Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim constructs and executes a vimgrep command using an insufficiently escaped typeref: or typename: value from a tags file, a…
- CVE-2026-73076HIGHCVSS 8.4EG 8.42026-08-11
Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimball member named .VimballRecord to overwrite the installation record with attacker-chosen commands. When vimball#RmVimbal…
- CVE-2026-73367HIGHCVSS 7.2EG 7.22026-08-18
Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.
- CVE-2026-7373HIGHCVSS 8.5EG 8.52026-05-15
Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that allows a user to gain SYSTEM level control of a Windows host. When started the metasploitPostgreSQL service would start the postgres.exe child process which wo…
- CVE-2026-73851MEDIUMCVSS 6.1EG 6.12026-08-17
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who controls or tampers with the OpenAPI description consumed by Kiota can supply a file reference that resolves outside the manifest package (e.…
- CVE-2026-75569HIGHCVSS 7.7EG 7.72026-08-19
A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with writ…
- CVE-2026-76139HIGHCVSS 8.0EG 8.02026-08-19
A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitH…
- CVE-2026-79721HIGHCVSS 8.6EG 8.62026-09-08
Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when loaded by the project.
- CVE-2026-81305MEDIUMCVSS 6.8EG 6.82026-09-18
CM2507 IP cameras automatically execute a predetermined script from removable media without verifying its authenticity or integrity. An attacker with physical access to the device could supply a malicious script and execute arbitrary code …
- CVE-2026-82525MEDIUMCVSS 5.5EG 5.52026-09-03
Exterro FTK Imager before 8.3 contains an XML external entity (XXE) injection vulnerability that allows attackers to read arbitrary files from the host filesystem by embedding malicious external entity references and attacker-controlled XS…
- CVE-2026-8426HIGHCVSS 8.8EG 8.82026-05-21
Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/prepare_remote_upgrade/<remoteMPID>. An attacker who controls the remote package returned for a known marketplace item ID ca…
- CVE-2026-8428HIGHCVSS 8.8EG 8.82026-05-21
Concrete CMS 9.5.0 and below emits a CSRF token in the local_available_update.php view ($token->output('do_update')) but the corresponding do_update() method in concrete/controllers/single_page/dashboard/system/update/update.php never call…
- CVE-2026-86169HIGHCVSS 8.8EG 8.82026-09-05
Axolotl before 0.19.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None instead of False, causing the security guard to be bypassed. Attackers can execute arbitrary Python c…
- CVE-2026-86504HIGHCVSS 7.8EG 7.82026-09-07
In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution
- CVE-2026-8879HIGHCVSS 7.5EG 7.52026-06-03
Version 3.0.7 of the Securly Chrome Extension dynamically registers content13.min.js as a content script via chrome.scripting.registerContentScripts() at runtime. This script is NOT declared in manifest.json and bypasses Chrome Web Store s…
- CVE-2026-89332MEDIUMCVSS 5.5EG 5.52026-09-11
Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon Kiro IDE before version 0.8.135 might allow remote unauthenticated actors to obtain sensitive information from a developer workstation. Crafte…
Map vulnerabilities like CWE-829 to your infrastructure
EchelonGraph correlates every CVE — across CWE-829 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →