VYPR

CWE-183

Permissive List of Allowed Inputs

BaseDraft

Description

The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are explicitly allowed by policy because the inputs are assumed to be safe, but the list is too permissive - that is, it allows an input that is unsafe, leading to resultant weaknesses.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-120 · CAPEC-3 · CAPEC-43 · CAPEC-71

CVEs mapped to this weakness (56)

page 3 of 3
  • CVE-2026-46341MedJul 16, 2026
    risk 0.33cvss 6.1epss 0.00

    The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store. Prior to 0.9.21, the fetch-apify-docs tool in src/tools/common/fetch_apify_docs.ts validates allowlisted documentation…

  • CVE-2026-41240MedApr 23, 2026
    risk 0.33cvss 6.1epss 0.00

    DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Versions prior to 3.4.0 have an inconsistency between FORBID_TAGS and FORBID_ATTR handling when function-based ADD_TAGS is used. Commit c361baa added an early exit for FORBID_ATTR at line 1214. The…

  • CVE-2020-1694MedSep 16, 2020
    risk 0.32cvss 4.9epss 0.02

    A flaw was found in all versions of Keycloak before 10.0.0, where the NodeJS adapter did not support the verify-token-audience. This flaw results in some users having access to sensitive information outside of their permissions.

  • CVE-2026-42042MedApr 24, 2026
    risk 0.28cvss 5.4epss 0.00

    Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library's XSRF token protection logic uses JavaScript truthy/falsy semantics instead of strict boolean comparison for the withXSRFToken config property. When this property is…

  • CVE-2024-47565MedOct 8, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate that user input complies with a list of allowed values. This could allow an authenticated remote attacker to compromise the integrity of…

  • CVE-2022-42469MedApr 11, 2023
    risk 0.28cvss 4.3epss 0.00

    A permissive list of allowed inputs vulnerability [CWE-183] in FortiGate version 7.2.3 and below, version 7.0.9 and below Policy-based NGFW Mode may allow an authenticated SSL-VPN user to bypass the policy via bookmarks in the web portal.

  • CVE-2026-33769MedMar 24, 2026
    risk 0.27cvss 5.3epss 0.00

    Astro is a web framework. From version 2.10.10 to before version 5.18.1, this issue concerns Astro's remotePatterns path enforcement for remote URLs used by server-side fetchers such as the image optimization endpoint. The path matching logic for /* wildcards is unanchored, so a…

  • CVE-2026-32881MedMar 20, 2026
    risk 0.27cvss 5.3epss 0.00

    ewe is a Gleam web server. ewe is a Gleam web server. Versions 0.6.0 through 3.0.4 are vulnerable to authentication bypass or spoofed proxy-trust headers. Chunked transfer encoding trailer handling merges declared trailer fields into req.headers after body parsing, but the…

  • CVE-2025-68949MedJan 13, 2026
    risk 0.27cvss 5.3epss 0.00

    n8n is an open source workflow automation platform. From 1.36.0 to before 2.2.0, the Webhook node’s IP whitelist validation performed partial string matching instead of exact IP comparison. As a result, an incoming request could be accepted if the source IP address merely…

  • CVE-2026-44111MedMay 6, 2026
    risk 0.21cvss 4.3epss 0.00

    OpenClaw before 2026.4.15 contains an arbitrary file read vulnerability in the QMD backend memory_get function that allows callers to read any Markdown files within the workspace root. Attackers with access to the memory tool can bypass path restrictions by providing arbitrary…

  • CVE-2026-63649MedAug 14, 2026
    risk 0.20cvss —epss 0.00

    The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via crafted options that bypass whitelist checks

  • CVE-2026-11525LowJun 17, 2026
    risk 0.17cvss 3.7epss 0.00

    Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or None as a substring, rather than the case-insensitive exact match specified by RFC 6265. Non-spec values are silently mapped to one of the three standard tokens.…

  • CVE-2026-16129MedJul 18, 2026
    risk 0.00cvss 5.3epss 0.00

    A vulnerability has been found in princezuda SafestClaw up to 4.2.4. This vulnerability affects the function ShellAction._validate_command of the file src/safestclaw/actions/shell.py of the component Built-in Web Interface. Such manipulation leads to incomplete blacklist. An…

  • CVE-2026-15625MedJul 14, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was found in nextlevelbuilder GoClaw 3.11.3. Affected by this issue is the function ExecApprovalManager.CheckCommand of the file internal/tools/exec_approval.go. The manipulation results in incomplete blacklist. The attack can be executed remotely. The exploit…

  • CVE-2026-59802HigJul 8, 2026
    risk 0.00cvss 8.2epss 0.00

    PasswordPusher before 2.8.1 accepts data URI schemes in URL push payloads due to insufficient validation in the valid_url function. Attackers can create malicious pushes containing data:text/html URIs that execute arbitrary JavaScript in victims' browsers when clicked, enabling…

  • CVE-2024-38522MedJun 28, 2024
    risk 0.00cvss 6.3epss 0.00

    Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. The CSP policy applied on the `tips.hushline.app` website and bundled by default in this repository is trivial to bypass. This vulnerability has been patched in version 0.1.0.