CWE-913: Improper Control of Dynamically-Managed Code Resources
The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements.
77 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-68613 — n8n Vulnerable to Remote Code Execution via Expression Injection
- CVE-2026-23830 — SandboxJS has Sandbox Escape via Unprotected AsyncFunction Constructor
- CVE-2026-22709 — vm2 has a Sandbox Escape
- CVE-2025-25270 — Remote Code Execution via Unauthenticated Configuration Manipulation
- CVE-2025-66398 — Signal K Server has Unauthenticated State Pollution leading to Remote Code Execution (RCE)
- CVE-2026-25049 — n8n Has an Expression Escape Vulnerability Leading to RCE
- CVE-2026-33286 — Graphiti Affected by Arbitrary Method Execution via Unvalidated Relationship Names
- CVE-2026-34156 — NocoBase Affected by Sandbox Escape to RCE via console._stdout Prototype Chain Traversal in Workflow Script Node
- CVE-2025-13659 — Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a
- CVE-2025-13426 — Improper Sandboxing in Google Apigee's JavaCallout Policy Allows for Remote Code Execution
- CVE-2024-27135 — Apache Pulsar: Improper Input Validation in Pulsar Function Worker allows Remote Code Execution
- CVE-2026-47208 — vm2: Sandbox Breakout Using Promise Species
- CVE-2026-47137 — vm2: GHSA-8hg8-63c5-gwmx patch bypass: nesting:true without explicit require still allows full RCE
- CVE-2026-47131 — vm2: Sandbox Escape
- CVE-2026-47698 — vm2: Sandbox Breakout Using Dangerous Host Proto Mutators
- CVE-2026-53753 — Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API
- CVE-2026-47210 — vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass
- CVE-2026-44336 — PraisonAI MCP `tools/call` path-traversal and RCE via Python `.pth` injection
- CVE-2025-54065 — GZDoom engine allows arbitrary code execution via ZScript actor states
- CVE-2026-48700 — An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0. When a regular file's path is passed as a URI
Recently published
- CVE-2026-41870 — Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch Server (Nutch REST API)
- CVE-2026-65181 — Apache Impala: RCE via External Data Source Class Loading
- CVE-2026-85408 — Eleveo Quality Management Conversation events dynamically-determined object attributes
- CVE-2026-84430 — gouguoa edit_personal Endpoint Index.php update dynamically-determined object attributes
- CVE-2026-48105 — Arc Enterprise cluster FSM applyRegisterFile accepts arbitrary file paths without validation, enabling cluster-wide path-traversal worm primitive
- CVE-2026-76023 — Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173 allowed a remote attacker wh
- CVE-2026-71470 — Acm-search-v2-rhel9: search-v2-operator: search cr imageoverride/arguments/envvar flow unsanitized into pods running impersonating sa
- CVE-2026-47698 — vm2: Sandbox Breakout Using Dangerous Host Proto Mutators
- CVE-2026-73226 — Electerm WebSocket `upgrade-func` and `fs` handlers allow arbitrary method/function invocation due to missing method-name allowlist
- CVE-2026-53753 — Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API
- CVE-2026-48775 — LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading
- CVE-2026-47210 — vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass
- CVE-2026-47208 — vm2: Sandbox Breakout Using Promise Species
- CVE-2026-47137 — vm2: GHSA-8hg8-63c5-gwmx patch bypass: nesting:true without explicit require still allows full RCE
- CVE-2026-47131 — vm2: Sandbox Escape
- CVE-2026-48700 — An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0. When a regular file's path is passed as a URI
- CVE-2026-44336 — PraisonAI MCP `tools/call` path-traversal and RCE via Python `.pth` injection
- CVE-2026-7381 — Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting
- CVE-2026-5251 — z-9527 admin User Update Endpoint user.js dynamically-determined object attributes
- CVE-2026-5248 — gougucms User Registration Login.php reg_submit dynamically-determined object attributes