VYPR

CWE-829

Inclusion of Functionality from Untrusted Control Sphere

BaseIncomplete

Description

The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-175 · CAPEC-201 · CAPEC-228 · CAPEC-251 · CAPEC-252 · CAPEC-253 · CAPEC-263 · CAPEC-538 · CAPEC-549 · CAPEC-640 · CAPEC-660 · CAPEC-695 · CAPEC-698

CVEs mapped to this weakness (339)

page 16 of 17
  • CVE-2025-15612MedMar 27, 2026
    risk 0.24cvss 4.8epss 0.00

    Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k/--insecure flag, disabling SSL/TLS certificate validation. Attackers with network access can perform man-in-the-middle attacks to intercept and modify…

  • CVE-2026-59831MedJul 9, 2026
    risk 0.22cvss 4.4epss 0.00

    GitHub CLI (gh) is GitHub’s official command line tool. From 2.10.0 through 2.95.0, connecting to a malicious Codespace with gh codespace jupyter can allow command execution because the command opens a JupyterLab URL supplied by a process inside the Codespace without…

  • CVE-2026-54325MedJun 23, 2026
    risk 0.22cvss 4.4epss 0.00

    Pi is a minimal terminal coding harness. Pi before 0.79.0 loaded project-local configuration and resources from a repository's .pi directory without first asking the user to trust that repository. This included project-local extensions, which are executable TypeScript or…

  • CVE-2024-52976MedMay 1, 2025
    risk 0.22cvss 4.4epss 0.00

    Inclusion of functionality from an untrusted control sphere in Elastic Agent subprocess, osqueryd, allows local attackers to execute arbitrary code via parameter injection. An attacker requires local access and the ability to modify osqueryd configurations.

  • CVE-2022-31021LowJan 16, 2024
    risk 0.21cvss 3.3epss 0.00

    Ursa is a cryptographic library for use with blockchains. A weakness in the Hyperledger AnonCreds specification that is not mitigated in the Ursa and AnonCreds implementations is that the Issuer does not publish a key correctness proof demonstrating that a generated private key…

  • CVE-2013-1945LowOct 31, 2019
    risk 0.21cvss 3.3epss 0.00

    ruby193 uses an insecure LD_LIBRARY_PATH setting.

  • CVE-2025-52655LowOct 10, 2025
    risk 0.20cvss 3.1epss 0.00

    Inclusion of Functionality from Untrusted Control Sphere vulnerability in HCL MyXalytics. v6.6 allows Loading third-party scripts without integrity checks or validation can allow external code run in the application's context, risking data exposure.

  • CVE-2025-54558MedJul 25, 2025
    risk 0.20cvss 4.1epss 0.00

    OpenAI Codex CLI before 0.9.0 auto-approves ripgrep (aka rg) execution even with the --pre or --hostname-bin or --search-zip or -z flag.

  • CVE-2025-68162LowDec 16, 2025
    risk 0.18cvss 2.7epss 0.00

    In JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configuration

  • CVE-2022-4134LowMar 6, 2023
    risk 0.18cvss 2.8epss 0.00

    A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images.

  • CVE-2026-0303LowSep 10, 2026
    risk 0.16cvss —epss 0.00

    A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file.

  • CVE-2026-65908HigJul 23, 2026
    risk 0.00cvss 8.6epss 0.00

    In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open

  • CVE-2026-64811HigJul 23, 2026
    risk 0.00cvss 7.8epss 0.00

    In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration

  • CVE-2026-64809HigJul 23, 2026
    risk 0.00cvss 8.4epss 0.00

    In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter

  • CVE-2026-64808HigJul 23, 2026
    risk 0.00cvss 8.4epss 0.00

    In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling

  • CVE-2026-64807HigJul 23, 2026
    risk 0.00cvss 7.8epss 0.00

    In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration

  • CVE-2026-64806HigJul 23, 2026
    risk 0.00cvss 8.4epss 0.00

    In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter

  • CVE-2026-64805HigJul 23, 2026
    risk 0.00cvss 8.4epss 0.00

    In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling

  • CVE-2026-64804HigJul 23, 2026
    risk 0.00cvss 8.4epss 0.00

    In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling

  • CVE-2026-44359CriJul 20, 2026
    risk 0.00cvss 10.0epss 0.02

    Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow is triggered by pull_request_target and multiple jobs check out the attacker's fork code and execute it with access to repository…