CWE-184: Incomplete List of Disallowed Inputs
The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.
185 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-49869 — Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`
- CVE-2026-33396 — OneUptime has sandbox escape in Synthetic Monitor Playwright runtime allows project members to execute arbitrary commands on Probe
- CVE-2026-28363 — In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviation
- CVE-2026-28783 — Craft has a Twig Function Blocklist Bypass
- CVE-2026-32940 — SiYuan has a SanitizeSVG bypass via data:text/xml in getDynamicIcon (incomplete fix for CVE-2026-29183)
- CVE-2025-58361 — Promptcraft Forge Studio's incomplete URL check is vulnerable to XSS via SVG
- CVE-2026-22609 — Fickling has Static Analysis Bypass via Incomplete Dangerous Module Blocklist
- CVE-2026-22608 — Fickling vulnerable to use of ctypes and pydoc gadget chain to bypass detection
- CVE-2026-22607 — Fickling Blocklist Bypass: cProfile.run()
- CVE-2026-22606 — Fickling has a bypass via runpy.run_path() and runpy.run_module()
- CVE-2026-25951 — FUXA has a Path Traversal Sanitization Bypass
- CVE-2026-79696 — Remote Code Execution in Google ADK for Python via Incomplete Standard Library Denylist
- CVE-2026-33139 — PySpector: Plugin Sandbox Bypass leads to Arbitrary Code Execution
- CVE-2026-65083 — NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an in
- CVE-2026-47392 — PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode)
- CVE-2025-58353 — Promptcraft Forge Studio: Complete Sanitizer Bypass Enables XSS via Overlapping Patterns
- CVE-2026-34415 — Xerte Online Toolkits File Upload RCE via elfinder Connector
- CVE-2026-70470 — Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
- CVE-2026-55743 — OpenHuman desktop agent shell tool sandbox bypass leads to arbitrary command execution
- CVE-2026-19429 — An incomplete patch for CVE-2026-33001 in Jenkins Project Jenkins through LTS 2.555.3 allows an authenticated remote att
Recently published
- CVE-2026-86199 — PocketMine-MP before 5.43.1 Denial of Service via unauthenticated login
- CVE-2026-79696 — Remote Code Execution in Google ADK for Python via Incomplete Standard Library Denylist
- CVE-2026-82536 — Roo-Code 3.54.0 Auto-Approve Bypass via Shell Command Pipe Operator
- CVE-2026-33197 — BDS Module Bypass Secure Boot Advisory
- CVE-2026-85787 — An incomplete list of disallowed inputs in the SQL validation component of Amazon awslabs postgres-mcp-server
- CVE-2026-77124 — Nexus Repository 3 - Script Execution Disable Setting Not Enforced
- CVE-2026-84370 — SVGO: removeScripts allows executable links through namespace and control-character bypasses
- CVE-2026-84218 — Org.jolokia/jolokia-core: incomplete jndi denylist in jolokia jsr-160 proxy (bypass of cve-2018-1000130 fix)
- CVE-2026-56547 — An input reflection vulnerability affects HCL Traveler
- CVE-2026-52776 — Trestle URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0
- CVE-2026-65083 — NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an in
- CVE-2026-76072 — Continue CLI through 1.5.47 Incomplete Destructive Command Denylist in Headless and Auto Mode
- CVE-2026-62676 — Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py
- CVE-2026-72860 — 9router Server-Side Request Forgery via /api/provider-nodes/validate Because the IPv4-Mapped IPv6 Denylist Check Is Unreachable
- CVE-2026-68921 — DiceBear: SVG injection via the unescaped rotate option in @dicebear/core (and fontSize/fontWeight in @dicebear/initials)
- CVE-2026-49825 — lxml: javascript: URL bypass in Cleaner via xlink:href
- CVE-2026-45741 — Gotenberg: SSRF deny-list bypass in IsPublicIP via IPv6 6to4 / NAT64 / site-local prefixes
- CVE-2026-74886 — openssl_encrypt before 1.4.0 Plugin Import Guard Bypass
- CVE-2026-73650 — SVGO: removeScripts plugin leaves some executable scripts intact
- CVE-2026-73484 — Flowise before 3.1.3 Sandbox Escape via Pandas Methods
More specific weaknesses
- CWE-692 — Incomplete Denylist to Cross-Site Scripting