CWE-829
Inclusion of Functionality from Untrusted Control Sphere
Description
The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-175 · CAPEC-201 · CAPEC-228 · CAPEC-251 · CAPEC-252 · CAPEC-253 · CAPEC-263 · CAPEC-538 · CAPEC-549 · CAPEC-640 · CAPEC-660 · CAPEC-695 · CAPEC-698
CVEs mapped to this weakness (313)
page 15 of 16| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-54558 | Med | 0.20 | 4.1 | 0.00 | Jul 25, 2025 | OpenAI Codex CLI before 0.9.0 auto-approves ripgrep (aka rg) execution even with the --pre or --hostname-bin or --search-zip or -z flag. | ||
| CVE-2025-68162 | Low | 0.18 | 2.7 | 0.00 | Dec 16, 2025 | In JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configuration | ||
| CVE-2022-4134 | Low | 0.18 | 2.8 | 0.00 | Mar 6, 2023 | A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images. | ||
| CVE-2026-65908 | Hig | 0.00 | 8.6 | 0.00 | Jul 23, 2026 | In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open | ||
| CVE-2026-64811 | Hig | 0.00 | 7.8 | 0.00 | Jul 23, 2026 | In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration | ||
| CVE-2026-64809 | Hig | 0.00 | 8.4 | 0.00 | Jul 23, 2026 | In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter | ||
| CVE-2026-64808 | Hig | 0.00 | 8.4 | 0.00 | Jul 23, 2026 | In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling | ||
| CVE-2026-64807 | Hig | 0.00 | 7.8 | 0.00 | Jul 23, 2026 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration | ||
| CVE-2026-64806 | Hig | 0.00 | 8.4 | 0.00 | Jul 23, 2026 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter | ||
| CVE-2026-64805 | Hig | 0.00 | 8.4 | 0.00 | Jul 23, 2026 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling | ||
| CVE-2026-64804 | Hig | 0.00 | 8.4 | 0.00 | Jul 23, 2026 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling | ||
| CVE-2026-44359 | Cri | 0.00 | 10.0 | 0.01 | Jul 20, 2026 | Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow is triggered by pull_request_target and multiple jobs check out the attacker's fork code and execute it with access to repository… | ||
| CVE-2026-16085 | Med | 0.00 | 5.3 | 0.00 | Jul 18, 2026 | A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. Affected is the function NewContextBuilder of the file pkg/agent/context.go. Such manipulation leads to inclusion of functionality from untrusted control sphere. The attack needs to be performed locally.… | ||
| CVE-2026-57860 | Hig | 0.00 | 7.8 | 0.00 | Jul 17, 2026 | ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI, automatically loads and executes the MCP servers defined in a repository's .mcp.json file on startup without user confirmation. A malicious repository can supply a crafted .mcp.json whose mcpServers entries specify… | ||
| CVE-2026-62222 | Hig | 0.00 | 7.8 | 0.00 | Jul 17, 2026 | OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted workspace plugins. Attackers with lower-trust caller access or control over configured input paths can execute or persist actions beyond their intended authorization level. | ||
| CVE-2026-50562 | Cri | 0.00 | — | 0.00 | Jul 15, 2026 | FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, artifacts built from untrusted pull request code in .github/workflows/preview-docs-build.yml and .github/workflows/preview-fastgpt-build.yml can be downloaded by… | ||
| CVE-2026-40501 | Hig | 0.00 | 8.8 | 0.00 | Jul 15, 2026 | Cherry Studio versions 1.2.2 through 1.9.12, fixed in commit 1518530, contain a remote code execution vulnerability in SearchService that allows remote attackers to execute arbitrary code by delivering malicious JavaScript through controlled search provider content loaded into… | ||
| CVE-2026-24226 | Med | 0.00 | 6.3 | 0.00 | Jul 14, 2026 | NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure. | ||
| CVE-2026-57102 | Hig | 0.00 | 8.8 | 0.01 | Jul 14, 2026 | Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2026-15519 | Med | 0.00 | 5.0 | 0.00 | Jul 13, 2026 | A vulnerability was found in usestrix strix up to 1.0.2. This affects an unknown function of the file system_prompt.jinja of the component PyPI Handler. Performing a manipulation results in inclusion of functionality from untrusted control sphere. The attack is possible to be… |
- risk 0.20cvss 4.1epss 0.00
OpenAI Codex CLI before 0.9.0 auto-approves ripgrep (aka rg) execution even with the --pre or --hostname-bin or --search-zip or -z flag.
- risk 0.18cvss 2.7epss 0.00
In JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configuration
- risk 0.18cvss 2.8epss 0.00
A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images.
- risk 0.00cvss 8.6epss 0.00
In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open
- risk 0.00cvss 7.8epss 0.00
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration
- risk 0.00cvss 8.4epss 0.00
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter
- risk 0.00cvss 8.4epss 0.00
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling
- risk 0.00cvss 7.8epss 0.00
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration
- risk 0.00cvss 8.4epss 0.00
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter
- risk 0.00cvss 8.4epss 0.00
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling
- risk 0.00cvss 8.4epss 0.00
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling
- risk 0.00cvss 10.0epss 0.01
Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow is triggered by pull_request_target and multiple jobs check out the attacker's fork code and execute it with access to repository…
- risk 0.00cvss 5.3epss 0.00
A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. Affected is the function NewContextBuilder of the file pkg/agent/context.go. Such manipulation leads to inclusion of functionality from untrusted control sphere. The attack needs to be performed locally.…
- risk 0.00cvss 7.8epss 0.00
ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI, automatically loads and executes the MCP servers defined in a repository's .mcp.json file on startup without user confirmation. A malicious repository can supply a crafted .mcp.json whose mcpServers entries specify…
- risk 0.00cvss 7.8epss 0.00
OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted workspace plugins. Attackers with lower-trust caller access or control over configured input paths can execute or persist actions beyond their intended authorization level.
- risk 0.00cvss —epss 0.00
FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, artifacts built from untrusted pull request code in .github/workflows/preview-docs-build.yml and .github/workflows/preview-fastgpt-build.yml can be downloaded by…
- risk 0.00cvss 8.8epss 0.00
Cherry Studio versions 1.2.2 through 1.9.12, fixed in commit 1518530, contain a remote code execution vulnerability in SearchService that allows remote attackers to execute arbitrary code by delivering malicious JavaScript through controlled search provider content loaded into…
- risk 0.00cvss 6.3epss 0.00
NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
- risk 0.00cvss 8.8epss 0.01
Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.00cvss 5.0epss 0.00
A vulnerability was found in usestrix strix up to 1.0.2. This affects an unknown function of the file system_prompt.jinja of the component PyPI Handler. Performing a manipulation results in inclusion of functionality from untrusted control sphere. The attack is possible to be…