CWE-829— Inclusion of Functionality from Untrusted Control Sphere
The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.— MITRE CWE catalog
362 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-829page 3 of 8
- CVE-2024-32011HIGHCVSS 8.8EG 8.82025-11-11
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to run arbitrary commands via the user interface. This user interface can be used via the network and allo…
- CVE-2025-62726HIGHCVSS 8.8EG 8.82025-10-30
n8n is an open source workflow automation platform. Prior to 1.113.0, a remote code execution vulnerability exists in the Git Node component available in both Cloud and Self-Hosted versions of n8n. When a malicious actor clones a remote re…
- CVE-2025-61592HIGHCVSS 8.8EG 8.82025-10-03
Cursor is a code editor built for programming with AI. In versions 1.7 and below, automatic loading of project-specific CLI configuration from the current working directory (<project>/.cursor/cli.json) could override certain global configu…
- CVE-2025-8714HIGHCVSS 8.8EG 8.82025-08-14
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-…
- CVE-2025-20236HIGHCVSS 8.8EG 8.82025-04-16
A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade a user to download arbitrary files, which could allow the attacker to execute arbitrary commands on the host of the tar…
- CVE-2025-27607HIGHCVSS 8.8EG 8.82025-03-07
Python JSON Logger is a JSON Formatter for Python Logging. Between 30 December 2024 and 4 March 2025 Python JSON Logger was vulnerable to RCE through a missing dependency. This occurred because msgspec-python313-pre was deleted by the owne…
- CVE-2024-13353HIGHCVSS 8.8EG 8.82025-02-21
The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.4 via several widgets. This makes it possible…
- CVE-2024-8252HIGHCVSS 8.8EG 8.82024-08-30
The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5 via the 'template' attribute of the clean-login-register shortcode. This makes it possible for authenticated attackers,…
- CVE-2024-24821HIGHCVSS 8.8EG 8.82024-02-09
Composer is a dependency Manager for the PHP language. In affected versions several files within the local working directory are included during the invocation of Composer and in the context of the executing user. As such, under certain co…
- CVE-2023-33559HIGHCVSS 8.8EG 8.82023-10-26
A local file inclusion vulnerability via the lang parameter in OcoMon before v4.0.1 allows attackers to execute arbitrary code by supplying a crafted PHP file.
- CVE-2023-2453HIGHCVSS 8.8EG 8.82023-09-05
There is insufficient sanitization of tainted file names that are directly concatenated with a path that is subsequently passed to a ‘require_once’ statement. This allows arbitrary files with the ‘.php’ extension for which the abso…
- CVE-2023-40195HIGHCVSS 8.8EG 8.82023-08-28
Deserialization of Untrusted Data, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Software Foundation Apache Airflow Spark Provider. When the Apache Spark provider is installed on an Airflow deployment, a…
- CVE-2023-2551HIGHCVSS 8.8EG 8.82023-05-05
PHP Remote File Inclusion in GitHub repository unilogies/bumsys prior to 2.1.1.
- CVE-2022-46302HIGHCVSS 8.8EG 8.82023-04-20
Broad access controls could allow site users to directly interact with the system Apache installation when providing the reverse proxy configurations for Tribe29's Checkmk <= 2.1.0p6, Checkmk <= 2.0.0p27, and all versions of Checkmk 1.6.0 …
- CVE-2022-34468HIGHCVSS 8.8EG 8.82022-12-22
An iframe that was not permitted to run scripts could do so if the user clicked on a <code>javascript:</code> link. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
- CVE-2022-30243HIGHCVSS 8.8EG 8.82022-07-15
Honeywell Alerton Visual Logic through 2022-05-04 allows unauthenticated programming writes from remote users. This enables code to be stored on the controller and then run without verification. A user with malicious intent can send a craf…
- CVE-2021-30507HIGHCVSS 8.8EG 8.82021-06-04
Inappropriate implementation in Offline in Google Chrome on Android prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
- CVE-2021-20443HIGHCVSS 8.8EG 8.82021-02-18
IBM Maximo for Civil Infrastructure 7.6.2 includes executable functionality (such as a library) from a source that is outside of the intended control sphere. IBM X-Force ID: 196619.
- CVE-2019-8154HIGHCVSS 8.8EG 8.82019-11-06
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with privileges to modify product catalogs can trigger PHP file inclusion through a crafted XML file…
- CVE-2019-11591HIGHCVSS 8.8EG 8.82019-04-29
The WebDorado Contact Form plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST[…
- CVE-2019-11590HIGHCVSS 8.8EG 8.82019-04-29
The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['actio…
- CVE-2019-9829HIGHCVSS 8.8EG 8.82019-03-15
Maccms 10 allows remote attackers to execute arbitrary PHP code by entering this code in a template/default_pc/html/art Edit action. This occurs because template rendering uses an include operation on a cache file, which bypasses the prohi…
- CVE-2018-18387HIGHCVSS 8.8EG 8.82018-10-29
playSMS through 1.4.2 allows Privilege Escalation through Daemon abuse.
- CVE-2022-41216HIGHCVSS 8.3EG 8.82023-02-22
Local File Inclusion vulnerability within Cloudflow allows attackers to retrieve confidential information from the system.
- CVE-2024-5762HIGHCVSS 8.1EG 8.82024-08-21
Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Zen Cart. Authentication is not required to exploit th…
- CVE-2021-30121HIGHCVSS 6.5EG 8.82021-07-09
Semi-authenticated local file inclusion The contents of arbitrary files can be returned by the webserver Example request: `https://x.x.x.x/KLC/js/Kaseya.SB.JS/js.aspx?path=C:\Kaseya\WebPages\dl.asp` A valid sessionId is required but can be…
- CVE-2026-79721HIGHCVSS 8.6EG 8.62026-09-08
Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when loaded by the project.
- CVE-2026-65908HIGHCVSS 8.6EG 8.62026-07-23
In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open
- CVE-2026-42089HIGHCVSS 8.6EG 8.62026-05-26
Yeoman Environment provides an API to discover, create, and run generators, and to configure where and how a generator is resolved. Versions 2.9.0 through 6.0.0 install missing local generator packages from caller-supplied package names wi…
- CVE-2026-5817HIGHCVSS 8.6EG 8.62026-05-26
The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing. This causes transformers.AutoTokenizer.from_pretrained() to import and…
- CVE-2026-5843HIGHCVSS 8.6EG 8.62026-05-26
The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the model_file configuration field in config.json. When a model…
- CVE-2026-12057HIGHCVSS 7.8EG 8.62026-06-15
When the application executes the JavaScript script embedded in the PDF within the sandbox, it fails to intercept some dangerous interfaces, which allows remote scripts to be loaded, resulting in arbitrary code execution.
- CVE-2023-5523HIGHCVSS 7.8EG 8.62023-10-20
Execution of downloaded content flaw in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote Code Execution
- CVE-2026-63277HIGHCVSS 8.5EG 8.52026-10-05
LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run J…
- CVE-2026-48124HIGHCVSS 8.5EG 8.52026-06-15
Cursor is a code editor built for programming with AI. In versions prior to 3.0.0, the Cursor Desktop could execute workspace-defined Claude hook commands from .claude/settings.local.json without dedicated user approval. A malicious worksp…
- CVE-2026-7373HIGHCVSS 8.5EG 8.52026-05-15
Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that allows a user to gain SYSTEM level control of a Windows host. When started the metasploitPostgreSQL service would start the postgres.exe child process which wo…
- CVE-2025-36355HIGHCVSS 8.5EG 8.52025-10-06
IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authenticated user to execute malicious scripts from outside of its control sphere.
- CVE-2025-54135HIGHCVSS 8.5EG 8.52025-08-05
Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions below 1.3.9, If the file is a dotfile, editing it requires approval but creating a new one doesn't. Hence, if…
- CVE-2024-45482HIGHCVSS 8.5EG 8.52025-03-25
An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the SSH server on B&R APROL <4.4-00P1 may allow an authenticated local attacker from a trusted remote server to execute malicious commands.
- CVE-2026-1342HIGHCVSS 7.9EG 8.52026-04-08
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a l…
- CVE-2026-104811HIGHCVSS 8.4EG 8.42026-10-05
DigitalCanion SA has discovered a vulnerability that allows remote attackers to execute arbitrary code on affected installations of the product. Authentication may be required to exploit this vulnerability. The specific flaw exists wit…
- CVE-2026-104809HIGHCVSS 8.4EG 8.42026-10-05
DigitalCanion has discovered a vulnerability that allows an attacker to cause the system to load an attacker-controlled .so file instead of the expected legitimate module. The loading mechanism relies on a predictable module name without a…
- CVE-2026-19884HIGHCVSS 8.4EG 8.42026-08-14
In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integration without requiring the user to trust the folder first. This affects applications built on Theia that include the git integration, such …
- CVE-2026-64809HIGHCVSS 8.4EG 8.42026-07-23
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter
- CVE-2026-64808HIGHCVSS 8.4EG 8.42026-07-23
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling
- CVE-2026-64806HIGHCVSS 8.4EG 8.42026-07-23
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter
- CVE-2026-64805HIGHCVSS 8.4EG 8.42026-07-23
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling
- CVE-2026-64804HIGHCVSS 8.4EG 8.42026-07-23
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling
- CVE-2026-47781HIGHCVSS 8.4EG 8.42026-06-11
PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-local plugins from a .pdm-plugins directory during initialization, allowing an attacker-controlled file in an untrusted…
- CVE-2026-43940HIGHCVSS 8.4EG 8.42026-05-08
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.7.16, the runWidget function in src/app/widgets/load-widget.js constructs a file path by directly concatenating user‑supplied wi…
Map vulnerabilities like CWE-829 to your infrastructure
EchelonGraph correlates every CVE — across CWE-829 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →