CWE-829

Inclusion of Functionality from Untrusted Control Sphere

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

298 vulnerabilities with CWE-829
CVE-2026-66141 HIGH
Exim < 4.99.5 - Inclusion of Functionality from Untrusted Control Sphere
CVSS 7.4
CVE-2026-65908 HIGH
Jetbrains PyCharm < 2026.1.4, 2026.2 - Inclusion of Functionality from Untrusted Control Sphere
CVSS 8.6
CVE-2026-64811 HIGH
Jetbrains IntelliJ Idea < 2026.2 - Inclusion of Functionality from Untrusted Control Sphere
CVSS 7.8
CVE-2026-64809 HIGH
Jetbrains PhpStorm < 2026.2 - Inclusion of Functionality from Untrusted Control Sphere
CVSS 8.4
CVE-2026-64808 HIGH
Jetbrains PhpStorm < 2026.2 - Inclusion of Functionality from Untrusted Control Sphere
CVSS 8.4
CVE-2026-64807 HIGH
Jetbrains WebStorm < 2026.2 - Inclusion of Functionality from Untrusted Control Sphere
CVSS 7.8
CVE-2026-64806 HIGH
Jetbrains WebStorm < 2026.2 - Inclusion of Functionality from Untrusted Control Sphere
CVSS 8.4
CVE-2026-64805 HIGH
Jetbrains WebStorm < 2026.2 - Inclusion of Functionality from Untrusted Control Sphere
CVSS 8.4
CVE-2026-64804 HIGH
Jetbrains WebStorm < 2026.2 - Inclusion of Functionality from Untrusted Control Sphere
CVSS 8.4
CVE-2026-47398 HIGH
PraisonAI < 4.6.40 agents_generator.py - Arbitrary Code Execution
CVSS 8.1
CVE-2026-45711 MEDIUM
Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs
CVSS 5.9
CVE-2026-44359 CRITICAL
Meshtastic GitHub repo vulnerable to Arbitrary Code Execution via pull_request_target Fork Checkout in CI Workflow
CVSS 10.0
CVE-2026-16085 MEDIUM
Sipeed PicoClaw context.go NewContextBuilder inclusion of functionality from untrusted control sphere
CVSS 5.3
CVE-2026-57860 HIGH
ForgeCode Arbitrary Code Execution via Unvetted .mcp.json in Untrusted Repository
CVSS 7.8
CVE-2026-62222 HIGH
OpenClaw < 2026.5.22 Untrusted Plugin Loading via Setup-mode
CVSS 7.8
CVE-2026-59867 HIGH
Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
CVSS 7.1
CVE-2026-59865 CRITICAL
Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
CVE-2026-59864 CRITICAL
Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions
CVE-2026-50562 CRITICAL
FastGPT: Untrusted PR artifacts are pushed and deployed by privileged preview workflows
CVE-2026-40501 HIGH
Cherry Studio RCE via SearchService nodeIntegration Misconfiguration
CVSS 8.8
CVE-2026-24226 MEDIUM
Nvidia TensorRT-LLM < v1.3.0 rc12 - Inclusion of Functionality from Untrusted Control Sphere
CVSS 6.3
CVE-2026-57102 HIGH
Visual Studio Code Security Feature Bypass Vulnerability
CVSS 8.8
CVE-2026-15519 MEDIUM
usestrix PyPI system_prompt.jinja inclusion of functionality from untrusted control sphere
CVSS 5.0
CVE-2026-59831 MEDIUM
GitHub CLI `gh codespace jupyter` could allow remote code execution when connecting to a malicious Codespace
CVSS 4.4
CVE-2026-50195 CRITICAL
containerd: CRI checkpoint import allows local image tag poisoning
CVSS 9.9
Details
Vulnerabilities 298