CWE-183: Permissive List of Allowed Inputs
The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are explicitly allowed by policy because the inputs are assumed to be safe, but the list is too permissive - that is, it allows an input that is unsafe, leading to resultant weaknesses.
46 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-3490 — picklescan - Universal Blocklist Bypass via pkgutil.resolve_name
- CVE-2026-33979 — Express XSS Sanitizer: allowedTags/allowedAttributes bypass leads to permissive sanitization (XSS risk)
- CVE-2026-54694 — NationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account Takeover
- CVE-2025-59457 — In JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on Windows
- CVE-2026-50189 — Appsmith: RCE via Supervisord XML-RPC Admin Interface Exposed via /supervisor Caddy Route
- CVE-2026-29514 — NetBox 4.3.5 - 4.5.4 RCE via RenderTemplateMixin
- CVE-2026-46391 — HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apis
- CVE-2024-1654 — Unauthorized write operations in PaperCut NG/MF
- CVE-2026-67345 — MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft
- CVE-2025-24349 — A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS allows a remote authenticat
- CVE-2026-41387 — OpenClaw < 2026.3.22 - Supply Chain Redirection via Incomplete Host Environment Sanitization
- CVE-2026-55581 — mcp-shell: Secure Mode Allowlist Bypass via Default `/bin/bash` Executable
- CVE-2026-21915 — JSI Virtual Lightweight Collector: Shell escape allows privilege escalation to root
- CVE-2026-40899 — DataEase has an Arbitrary File Read Vulnerability
- CVE-2026-2303 — Heap Out-of-Bounds Read in Go Driver GSSAPI C Wrappers enables application crash or information leak
- CVE-2026-4509 — PbootCMS File Upload file.php incomplete blacklist
- CVE-2024-38522 — CSP bypass in Hush Line
- CVE-2026-46608 — Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-33533)
- CVE-2026-42043 — Axios: Incomplete Fix for CVE-2025-62718 — NO_PROXY Protection Bypassed via RFC 1122 Loopback Subnet (127.0.0.0/8) in Axios 1.15.0
- CVE-2026-8918 — A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/
Recently published
- CVE-2026-54694 — NationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account Takeover
- CVE-2026-55581 — mcp-shell: Secure Mode Allowlist Bypass via Default `/bin/bash` Executable
- CVE-2026-63649 — The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated
- CVE-2026-67315 — axios 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 NO_PROXY Bypass via 0.0.0.0
- CVE-2026-67345 — MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft
- CVE-2026-66005 — Jan Local API Server CORS Origin Reflection via 0.0.0.0 Binding
- CVE-2026-16129 — princezuda SafestClaw Built-in Web shell.py ShellAction._validate_command incomplete blacklist
- CVE-2026-46341 — Apify MCP server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix Matching
- CVE-2026-15625 — nextlevelbuilder GoClaw exec_approval.go ExecApprovalManager.CheckCommand incomplete blacklist
- CVE-2026-59802 — PasswordPusher < 2.8.1 - Redirect-Based XSS via data URI in URL Push Payload
- CVE-2026-46608 — Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-33533)
- CVE-2026-50189 — Appsmith: RCE via Supervisord XML-RPC Admin Interface Exposed via /supervisor Caddy Route
- CVE-2026-54316 — Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
- CVE-2026-8918 — A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/
- CVE-2026-11525 — undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching
- CVE-2026-3490 — picklescan - Universal Blocklist Bypass via pkgutil.resolve_name
- CVE-2026-46391 — HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apis
- CVE-2026-44111 — OpenClaw < 2026.4.15 - Arbitrary Markdown File Read via QMD memory_get
- CVE-2026-43574 — OpenClaw < 2026.4.12 - Improper Authorization via Empty Approver Lists
- CVE-2026-29514 — NetBox 4.3.5 - 4.5.4 RCE via RenderTemplateMixin