CWE-184

Incomplete List of Disallowed Inputs

Parent: CWE-693 - Protection Mechanism Failure

The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.

161 vulnerabilities with CWE-184
CVE-2026-54513 HIGH
jackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
CVSS 8.1
CVE-2026-54512 HIGH
Jackson Databind - PolymorphicTypeValidator Bypass via Generic Type Parameters
CVSS 8.1
CVE-2026-56315 CRITICAL
picklescan - Remote Code Execution via Unblocked Standard Library Modules
CVSS 9.8
CVE-2026-53873 CRITICAL
picklescan - Arbitrary Code Execution via profile.run() Blocklist Bypass
CVSS 9.8
CVE-2026-55743 CRITICAL
OpenHuman desktop agent shell tool sandbox bypass leads to arbitrary command execution
CVSS 9.6
CVE-2026-44587 MEDIUM
CarrierWave has a denylisted_content_type bypass via Unescaped Regex Metacharacters
CVSS 4.7
CVE-2026-53864 HIGH
OpenClaw < 2026.5.26 - Insufficient Environment Variable Sanitization in Node.js Control Variables
CVSS 8.1
CVE-2026-53861 MEDIUM
OpenClaw < 2026.5.6 - Allowlist Bypass via Combined POSIX Inline Flags on macOS
CVSS 6.6
CVE-2026-53855 HIGH
OpenClaw < 2026.4.2 - Shell Positional Parameters Bypass in Inline-Eval Checks
CVSS 8.1
CVE-2026-53848 MEDIUM
OpenClaw < 2026.5.26 - Exec Allowlist Bypass via Transparent Command Wrappers
CVSS 4.3
CVE-2026-53836 HIGH
OpenClaw < 2026.5.12 - Allowlist Bypass via PowerShell Encoded-Command Aliases
CVSS 8.8
CVE-2026-48557 HIGH
Spatie Laravel Media Library < 11.23.0 File Upload Restriction Bypass via FileAdder.php
CVSS 8.8
CVE-2026-44287 MEDIUM
FastGPT: sandbox escape to RCE - code-sandbox regex /\bimport\s*\(/ is bypassable
CVSS 6.3
CVE-2026-44463 HIGH
Zed: Allowlist Bypass via Environment Variable Injection in Terminal Tool Permissions
CVSS 8.6
CVE-2026-44462 MEDIUM
Zed: Allowlist Bypass via Bash Variable Expansion Chain in Terminal Tool Permissions
CVSS 6.4
CVE-2026-45037 HIGH
Tabby: Unsafe protocol handler execution via terminal linkifier allows arbitrary OS protocol invocation
CVSS 7.1
CVE-2026-42590 HIGH
Gotenberg: ExifTool group-prefix syntax bypasses dangerous-tag blocklist
CVSS 8.2
CVE-2026-40893 HIGH
Gotenberg: ExifTool Dangerous Tag Blocklist Bypass via Group-Prefixed Tag Names Allows Arbitrary File Rename and Move
CVSS 8.2
CVE-2026-43929 HIGH
ssrfcheck: Server-Side Request Forgery (SSRF) and Incomplete List of Disallowed Inputs
CVSS 8.2
CVE-2026-43991 HIGH
JunoClaw: plugin-shell shell-injection bypass via substring blocklist
CVSS 8.4
CVE-2026-45006 HIGH
OpenClaw < 2026.4.23 - Unsafe Config Mutation via Gateway Tool Denylist Bypass
CVSS 8.8
CVE-2026-44993 MEDIUM
OpenClaw < 2026.4.20 - Direct Message Misclassification in Feishu Card Actions
CVSS 5.4
CVE-2026-44115 HIGH
OpenClaw < 2026.4.22 - Shell Expansion Bypass in Unquoted Heredocs via Exec Allowlist
CVSS 8.8
CVE-2026-44114 HIGH
OpenClaw < 2026.4.20 - Environment Variable Namespace Collision via Workspace dotenv
CVSS 7.8
CVE-2026-43584 HIGH
OpenClaw < 2026.4.10 - Insufficient Environment Variable Denylist in Exec Policy
CVSS 8.8
Details
Vulnerabilities 161