CWE-829
Inclusion of Functionality from Untrusted Control Sphere
The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
298 vulnerabilities with CWE-829
CVE-2026-5843
HIGH
Docker Model Runner container-to-host code execution via MLX-LM model_file importlib loading
CVSS 8.2
CVE-2026-5817
HIGH
Docker Model Runner container-to-host code execution via unsandboxed trust_remote_code in Python inference backends
CVSS 8.2
CVE-2026-8428
HIGH
CSRF token is not validated in the core CMS update controller for Concrete CMS 9.5.0 and below
CVSS 8.8
CVE-2026-8426
HIGH
Concrete CMS 9.5.0 and below is vulnerable to CSRF on prepare_remote_upgrade() leading to one-request RCE via package overwrite
CVSS 8.8
CVE-2026-7373
HIGH
Metasploit Pro on Windows: Local Privilege Escalation via OpenSSL Configuration File Loading
CVE-2026-44312
MEDIUM
css_parser allows to MITM included https css urls
CVSS 5.8
CVE-2026-44484
CRITICAL
Compromise of PyTorch Lightning PyPi Package Versions
CVSS 9.8
CVE-2026-43999
CRITICAL
vm2: NodeVM builtin allowlist bypass via `module` builtin's `Module._load` allows sandbox escape
CVSS 9.9
CVE-2026-44995
HIGH
OpenClaw < 2026.4.20 - Arbitrary Code Execution via MCP stdio Environment Variables
CVSS 7.3
CVE-2026-45184
MEDIUM
Kdenlive < 26.04.1 - Inclusion of Functionality from Untrusted Control Sphere via Proxy Parameters
CVSS 6.5
CVE-2026-44336
CRITICAL
PraisonAI MCP `tools/call` path-traversal and RCE via Python `.pth` injection
CVSS 9.6
CVE-2026-43944
CRITICAL
electerm: dangerous code can be run through links or command line
CVSS 9.6
CVE-2026-43940
HIGH
electerm: Path traversal in electerm runWidget leads to arbitrary code execution
CVSS 8.4
CVE-2026-43571
HIGH
OpenClaw < 2026.4.10 - Untrusted Workspace Plugin Shadow Resolution in Channel Setup
CVSS 8.8
CVE-2026-43569
HIGH
OpenClaw < 2026.4.9 - Untrusted Provider Plugin Auto-enablement via Workspace Provider Auth
CVSS 8.8
CVE-2026-43003
HIGH
OpenStack ironic-python-agent <11.5.0 - Code Injection
CVSS 8.0
CVE-2026-41396
HIGH
OpenClaw < 2026.3.31 - Environment Variable Override of Plugin Trust Root
CVSS 7.8
CVE-2026-42510
MEDIUM
OpenStack Ironic <=25.0.0 - Command Injection
CVSS 6.6
CVE-2026-6357
MEDIUM
pip self-update functionality can import newly installed modules after wheel installation
CVE-2026-41355
HIGH
OpenShell < 2026.3.28 - Arbitrary Code Execution via Mirror Mode Sandbox File Conversion
CVSS 7.3
CVE-2026-41336
HIGH
OpenClaw < 2026.3.31 - Arbitrary Hook Code Execution via OPENCLAW_BUNDLED_HOOKS_DIR Environment Variable Override
CVSS 7.8
CVE-2026-6859
HIGH
Instructlab: instructlab: arbitrary code execution due to hardcoded `trust_remote_code=true`
CVSS 8.8
CVE-2026-40903
CRITICAL
Goshs - ArtiPACKED Vulnerability – GitHub Actions Credential Persistence
CVSS 9.1
CVE-2026-41295
HIGH
OpenClaw < 2026.4.2 - Untrusted Workspace Channel Shadow Code Execution during Built-in Channel Setup
CVSS 7.8
CVE-2026-41253
MEDIUM
iTerm2 < 3.6.9 - Remote Code Execution via DCS 2000p and OSC 135 Data
CVSS 6.9
Details
Vulnerabilities
298