CWE-829: Inclusion of Functionality from Untrusted Control Sphere
The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
218 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-32463 — Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
- CVE-2025-34074 — Lucee Admin Interface Authenticated Remote Code Execution via Scheduled Job File Write
- CVE-2026-1699 — In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_tar
- CVE-2025-34060 — Monero Forum Remote Code Execution via Arbitrary File Read and Cookie Forgery
- CVE-2025-66022 — FACTION Unauthenticated Custom Extension Upload leads to RCE
- CVE-2026-33075 — FastGPT has Arbitrary Code Execution in GitHub Actions via pull_request_target in fastgpt-preview-image.yml
- CVE-2025-65964 — n8n Vulnerable to Remote Code Execution via Git Node Custom Pre-Commit Hook
- CVE-2025-36852 — Build Cache Poisoning via Untrusted Pull Requests
- CVE-2025-0982 — Sandbox Escape in Google Cloud Application Integration's JavaScript Task (Rhino Engine)
- CVE-2025-27607 — Python JSON Logger has a Potential RCE via missing `msgspec-python313-pre` dependency
- CVE-2025-53546 — Folo allows secrets exfiltration via `pull_request_target`
- CVE-2025-8714 — PostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql client
- CVE-2025-62726 — n8n Vulnerable to Remote Code Execution via Git Node Pre-Commit Hook
- CVE-2025-61592 — Cursor CLI: Arbitrary Code Execution Possible through Permissive CLI Config
- CVE-2025-20236 — Cisco Webex App Client-Side Remote Code Execution Vulnerability
- CVE-2024-32011 — A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application i
- CVE-2024-24821 — Code execution and possible privilege escalation via compromised InstalledVersions.php or installed.php in Composer
- CVE-2026-22865 — Gradle's failure to disable repositories failing to answer can expose builds to malicious artifacts
- CVE-2026-22816 — Gradle fails to disable repositories which can expose builds to malicious artifacts
- CVE-2025-54135 — Cursor Agent is vulnerable to prompt injection via MCP Special Files
Recently published
- CVE-2026-0303 — Checkov by Prisma Cloud: Code Execution via Auto-Loaded Configuration File
- CVE-2026-79721 — Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously craft
- CVE-2026-86504 — In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed ho
- CVE-2026-86169 — Axolotl through 0.18.0 Remote Code Execution via Multipack Patching
- CVE-2026-82525 — Exterro FTK Imager < 8.3 XXE via Report.xml XSLT Processing
- CVE-2026-58569 — Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An authenticated use
- CVE-2026-18252 — Inclusion of Functionality from Untrusted Control Sphere in GitLab
- CVE-2026-76139 — Acm-operator-bundle: acm-operator-bundle: bundle build execs unpinned stolostron/release@master with full build credentials
- CVE-2026-75569 — Mce-operator-bundle: all github actions pinned by mutable tag, not commit sha
- CVE-2026-22306 — Critical flaw impacting OZOLS ERP's automatic update channel
- CVE-2026-62680 — Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
- CVE-2026-45272 — MyBooks: Remote Code Execution via SOCIAL_AUTH Key Name Injection in Python Config File
- CVE-2026-73073 — Vim: Arbitrary Ex Command Execution in C Omni-Completion
- CVE-2026-73367 — WordPress Easy Google Maps plugin < 1.14.2 - Remote File Inclusion vulnerability
- CVE-2026-73851 — Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass)
- CVE-2026-49986 — Cortex has Untrusted Project Bootstrap Code Execution via `CLAUDE_PROJECT_DIR`
- CVE-2026-19884 — In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integration without requiri
- CVE-2026-6464 — PostgreSQL psql COPY FROM STDIN early failure processes data lines as psql commands
- CVE-2026-18408 — PostgreSQL psql \unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql client
- CVE-2026-71471 — Acm-search-v2-rhel9: search-v2-operator: hub search cr collector.imageoverride propagated to every spoke as arbitrary container image