CWE-829— Inclusion of Functionality from Untrusted Control Sphere
The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.— MITRE CWE catalog
362 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-829page 8 of 8
- CVE-2019-4263MEDIUMCVSS 4.3EG 4.32019-07-11
IBM Content Navigator 3.0CD is vulnerable to local file inclusion, allowing an attacker to access a configuration file in the ICN server. IBM X-Force ID: 160015.
- CVE-2025-54558MEDIUMCVSS 4.1EG 4.12025-07-25
OpenAI Codex CLI before 0.9.0 auto-approves ripgrep (aka rg) execution even with the --pre or --hostname-bin or --search-zip or -z flag.
- CVE-2024-31144LOWCVSS 3.8EG 3.82025-02-14
For a brief summary of Xapi terminology, see: https://xapi-project.github.io/xen-api/overview.html#object-model-overview Xapi contains functionality to backup and restore metadata about Virtual Machines and Storage Repositories (SRs)…
- CVE-2022-31021LOWCVSS 3.3EG 3.32024-01-16
Ursa is a cryptographic library for use with blockchains. A weakness in the Hyperledger AnonCreds specification that is not mitigated in the Ursa and AnonCreds implementations is that the Issuer does not publish a key correctness proof dem…
- CVE-2022-33701LOWCVSS 3.3EG 3.32022-07-12
Improper access control vulnerability in KnoxCustomManagerService prior to SMR Jul-2022 Release 1 allows attacker to call PowerManaer.goToSleep method which is protected by system permission by sending braodcast intent.
- CVE-2013-1945LOWCVSS 3.3EG 3.32019-10-31
ruby193 uses an insecure LD_LIBRARY_PATH setting.
- CVE-2025-52655LOWCVSS 3.1EG 3.12025-10-10
Inclusion of Functionality from Untrusted Control Sphere vulnerability in HCL MyXalytics. v6.6 allows Loading third-party scripts without integrity checks or validation can allow external code run in the application's context, risking data…
- CVE-2022-4134LOWCVSS 2.8EG 2.82023-03-06
A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images.
- CVE-2025-68162LOWCVSS 2.7EG 2.72025-12-16
In JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configuration
- CVE-2026-49449LOWCVSS 2.5EG 2.52026-09-21
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. From 1.4.0 until 3.7.2, packages/renderer/MdToHtml/rules/katex.ts enables KaTeX's trust option for note content, allowing a note auth…
- CVE-2026-0303LOWCVSS 2.4EG 2.42026-09-10
A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file.
- CVE-2024-38537UnratedEG not assessed2024-07-02
Fides is an open-source privacy engineering platform. `fides.js`, a client-side script used to interact with the consent management features of Fides, used the `polyfill.io` domain in a very limited edge case, when it detected a legacy bro…
Map vulnerabilities like CWE-829 to your infrastructure
EchelonGraph correlates every CVE — across CWE-829 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →