CWE-829

Inclusion of Functionality from Untrusted Control Sphere

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

298 vulnerabilities with CWE-829
CVE-2026-6482 HIGH
Local Privilege Escalation via OpenSSL configuration file in Insight Agent
CVSS 7.8
CVE-2026-40959 CRITICAL
Luanti 5.0.0-5.15.1 - Lua Sandbox Escape via Crafted Mod
CVSS 9.3
CVE-2026-40313 CRITICAL
PraisonAI: ArtiPACKED Vulnerability via GitHub Actions Credential Persistence
CVSS 9.1
CVE-2026-40156 HIGH
PraisonAI Affected by Implicit Execution of Arbitrary Code via Automatic `tools.py` Loading
CVSS 7.8
CVE-2026-40154 CRITICAL
PraisonAI Affected by Untrusted Remote Template Code Execution
CVSS 9.3
CVE-2026-1342 HIGH
Security Vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
CVSS 8.5
CVE-2026-34442 MEDIUM
FreeScout: Host Header Injection Leading to External Resource Loading and Open Redirect in FreeScout
CVSS 5.4
CVE-2026-32920 HIGH
OpenClaw < 2026.3.12 - Arbitrary Code Execution via Auto-Discovery of Workspace Plugins
CVSS 8.4
CVE-2026-3991 HIGH
Elevation of Privileges in Symantec Data Loss Prevention Windows Endpoint
CVSS 7.8
CVE-2026-33075 HIGH
FastGPT has Arbitrary Code Execution in GitHub Actions via pull_request_target in fastgpt-preview-image.yml
CVSS 8.8
CVE-2026-28500 HIGH
ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain Attack
CVSS 8.6
CVE-2026-22217 MEDIUM
OpenClaw 2026.2.22 < 2026.2.23 - Arbitrary Binary Execution via $SHELL Environment Variable Trusted Prefix Fallback
CVSS 6.1
CVE-2026-4295 HIGH
Arbitrary code execution via crafted project files in Kiro IDE
CVSS 7.8
CVE-2026-4255 HIGH
TR-VISION HOME <= 2.0.5 - DLL Search Order Hijacking Privilege Escalation
CVSS 7.8
CVE-2026-28135 HIGH
WP Royal Elementor Addons <=1.7.1049 - Auth Bypass
CVSS 8.2
CVE-2026-1628 MEDIUM
Mattermost Desktop App <=5.13.3 - Open Redirect
CVSS 4.6
CVE-2026-26862 HIGH
CleverTap Web SDK < 1.15.2 - DOM-based Cross-Site Scripting via Window PostMessage Origin Validation Bypass
CVSS 8.3
CVE-2026-28372 HIGH
GNU inetutils <=2.7 - Privilege Escalation
CVSS 7.4
CVE-2026-27941 CRITICAL
OpenLIT <1.37.1 - Privilege Escalation
CVSS 9.9
CVE-2026-27615 HIGH
ADB Explorer <Beta 0.9.26022 - Command Injection
CVSS 7.8
CVE-2026-26974 CRITICAL
Slyde < 0.0.5 - Remote Code Execution via Malicious Plugin File Import
CVSS 9.8
CVE-2026-26959 HIGH
ADB Explorer <=0.9.26020 - Command Injection
CVSS 7.8
CVE-2026-22208 CRITICAL
OpenS100 < 753cf29 - Remote Code Execution via Unrestricted Lua Standard Library Access
CVSS 9.6
CVE-2026-26079 MEDIUM
Roundcube Webmail <1.5.13 & <1.6.13 - XSS
CVSS 4.7
CVE-2026-25931 HIGH
vscode-spell-checker <4.5.4 - Info Disclosure
CVSS 7.8
Details
Vulnerabilities 298