CWE-829

Inclusion of Functionality from Untrusted Control Sphere

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

298 vulnerabilities with CWE-829
CVE-2026-58116 CRITICAL
LLaMA-Factory 0.9.5 Remote Code Execution via WebUI Model Path
CVSS 9.8
CVE-2026-13751 MEDIUM
Snowflake CLI Server-Side Request Forgery via Arbitrary URL Fetch in !source/!load
CVSS 4.1
CVE-2026-55698 HIGH
pnpm < 10.34.2 and 11.0.0-11.5.2 - Lockfile-Selected Code Execution
CVSS 8.8
CVE-2026-55697 HIGH
pnpm: Repository-controlled configDependencies can select a pacquet native install engine
CVSS 7.5
CVE-2026-55487 HIGH
pnpm: manifest identity spoof satisfies allowBuilds and runs attacker lifecycle
CVSS 7.5
CVE-2026-54325 MEDIUM
earendil-works - Pi Loads Project-Local Extensions Without Approval
CVSS 4.4
CVE-2026-56447 HIGH
MISP remote code execution via arbitrary rdkafka configuration path
CVSS 7.2
CVE-2026-46580 HIGH
Eclipse Theia < 1.71.0 - Improper Neutralization of Input Used for LLM Prompting
CVSS 8.8
CVE-2026-44691 HIGH
Eclipse Theia < 1.69.0 - Inclusion of Functionality from Untrusted Control Sphere
CVSS 8.8
CVE-2026-44688 HIGH
Eclipse Theia < 1.71.0 - Improper Neutralization of Input Used for LLM Prompting
CVSS 8.8
CVE-2026-22551 MEDIUM
Eclipse Theia < 1.71.0 - Insertion of Sensitive Information Into Sent Data
CVSS 6.5
CVE-2026-22283 HIGH
Dell PowerFlex - Inclusion of Functionality from Untrusted Control Sphere
CVSS 7.5
CVE-2026-42089 HIGH
yeoman-environment Vulnerable to Arbitrary Package Installation without User Confirmation
CVSS 8.6
CVE-2026-48124 HIGH
Cursor Desktop sandbox escape via Claude hook configuration
CVE-2026-12057 HIGH
DoS + Remote Code Execution via PDF JavaScript in Foxit AI
CVSS 8.6
CVE-2026-53810 HIGH
OpenClaw < 2026.5.18 - Arbitrary Code Execution via Unscanned Marketplace Runtime Extension Metadata
CVSS 8.8
CVE-2026-52858 HIGH
Vim: Arbitrary Code Execution via Python Omni-Completion
CVSS 7.8
CVE-2026-47174 CRITICAL
Duck Site: Untrusted pull request code can trigger privileged production deployment
CVE-2026-47172 CRITICAL
Quest Bot: Untrusted pull request code can be built and deployed by privileged `workflow_run` deployment.
CVE-2026-46529 HIGH
PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen
CVSS 7.8
CVE-2026-47292 HIGH
Visual Studio Code MSSQL Extension Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-11269 HIGH
Google Chrome - Arbitrary Code Execution
CVSS 7.1
CVE-2026-8879 HIGH
Securly Chrome Extension < 3.0.7 - Denial of Service via Dynamic Content Script Injection
CVSS 7.5
CVE-2026-5241 CRITICAL
Policy Bypass in LightGlue Nested Config Resolution in huggingface/transformers
CVSS 9.6
CVE-2026-44358 HIGH
Espressif Shared GitHub DangerJS: Untrusted Search Path in DangerJS Action Entrypoint
CVSS 8.2
Details
Vulnerabilities 298