VYPR

CWE-183

Permissive List of Allowed Inputs

BaseDraft

Description

The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are explicitly allowed by policy because the inputs are assumed to be safe, but the list is too permissive - that is, it allows an input that is unsafe, leading to resultant weaknesses.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-120 · CAPEC-3 · CAPEC-43 · CAPEC-71

CVEs mapped to this weakness (52)

page 3 of 3
  • CVE-2024-47565MedOct 8, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate that user input complies with a list of allowed values. This could allow an authenticated remote attacker to compromise the integrity of…

  • CVE-2022-42469MedApr 11, 2023
    risk 0.28cvss 4.3epss 0.00

    A permissive list of allowed inputs vulnerability [CWE-183] in FortiGate version 7.2.3 and below, version 7.0.9 and below Policy-based NGFW Mode may allow an authenticated SSL-VPN user to bypass the policy via bookmarks in the web portal.

  • CVE-2026-33769MedMar 24, 2026
    risk 0.27cvss 5.3epss 0.00

    Astro is a web framework. From version 2.10.10 to before version 5.18.1, this issue concerns Astro's remotePatterns path enforcement for remote URLs used by server-side fetchers such as the image optimization endpoint. The path matching logic for /* wildcards is unanchored, so a…

  • CVE-2026-32881MedMar 20, 2026
    risk 0.27cvss 5.3epss 0.00

    ewe is a Gleam web server. ewe is a Gleam web server. Versions 0.6.0 through 3.0.4 are vulnerable to authentication bypass or spoofed proxy-trust headers. Chunked transfer encoding trailer handling merges declared trailer fields into req.headers after body parsing, but the…

  • CVE-2025-68949MedJan 13, 2026
    risk 0.27cvss 5.3epss 0.00

    n8n is an open source workflow automation platform. From 1.36.0 to before 2.2.0, the Webhook node’s IP whitelist validation performed partial string matching instead of exact IP comparison. As a result, an incoming request could be accepted if the source IP address merely…

  • CVE-2026-44111MedMay 6, 2026
    risk 0.21cvss 4.3epss 0.00

    OpenClaw before 2026.4.15 contains an arbitrary file read vulnerability in the QMD backend memory_get function that allows callers to read any Markdown files within the workspace root. Attackers with access to the memory tool can bypass path restrictions by providing arbitrary…

  • CVE-2026-11525LowJun 17, 2026
    risk 0.17cvss 3.7epss 0.00

    Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or None as a substring, rather than the case-insensitive exact match specified by RFC 6265. Non-spec values are silently mapped to one of the three standard tokens.…

  • CVE-2026-66005MedJul 24, 2026
    risk 0.00cvss 6.3epss 0.00

    Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that allows network-adjacent attackers to bypass trusted host restrictions by exploiting the server's replacement of user-configured trusted hosts with a wildcard…

  • CVE-2026-16129MedJul 18, 2026
    risk 0.00cvss 5.3epss 0.00

    A vulnerability has been found in princezuda SafestClaw up to 4.2.4. This vulnerability affects the function ShellAction._validate_command of the file src/safestclaw/actions/shell.py of the component Built-in Web Interface. Such manipulation leads to incomplete blacklist. An…

  • CVE-2026-15625MedJul 14, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was found in nextlevelbuilder GoClaw 3.11.3. Affected by this issue is the function ExecApprovalManager.CheckCommand of the file internal/tools/exec_approval.go. The manipulation results in incomplete blacklist. The attack can be executed remotely. The exploit…

  • CVE-2026-59802HigJul 8, 2026
    risk 0.00cvss 8.2epss 0.00

    PasswordPusher before 2.8.1 accepts data URI schemes in URL push payloads due to insufficient validation in the valid_url function. Attackers can create malicious pushes containing data:text/html URIs that execute arbitrary JavaScript in victims' browsers when clicked, enabling…

  • CVE-2024-38522MedJun 28, 2024
    risk 0.00cvss 6.3epss 0.00

    Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. The CSP policy applied on the `tips.hushline.app` website and bundled by default in this repository is trivial to bypass. This vulnerability has been patched in version 0.1.0.