Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key i
In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_tar
Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository
Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext trans
OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in Open
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, NodeVM's builtin allowlist can be bypassed when the modul
containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This
Slyde is a program that creates animated presentations from XML. In versions 0.0.4 and below, Node.js automatically impo
An issue pertaining to CWE-829: Inclusion of Functionality from Untrusted Control Sphere was discovered in Miazzy oa-fro
PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introdu
LLaMA-Factory through 0.9.5 contains a remote code execution vulnerability that allows attackers with WebUI access to ex
Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated sy
OpenS100 (the reference implementation S-100 viewer) prior to commit 753cf29 contains a remote code execution vulnerabil
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From versions 3.0.6 to before
PraisonAI is a multi-agent teams system. Prior to version 4.6.34, PraisonAI's MCP (Model Context Protocol) server (prais
A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-control
PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI treats remotely fetched template files as trusted e
Luanti 5 before 5.15.2, when LuaJIT is used, allows a Lua sandbox escape via a crafted mod.
PraisonAI is a multi-agent teams system. In versions 4.5.139 and below, the GitHub Actions workflows are vulnerable to A
goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can
A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically wit
FastGPT is an AI Agent building platform. In versions 4.14.8.3 and below, the fastgpt-preview-image.yml workflow is vuln
A flaw was found in InstructLab. The `linux_train.py` script hardcodes `trust_remote_code=True` when loading models from
OpenClaw before 2026.4.9 contains an authentication bypass vulnerability allowing untrusted workspace plugins to be auto
OpenClaw before 2026.4.10 contains a plugin trust bypass vulnerability that allows channel setup catalog lookups to reso
Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/prepa
Concrete CMS 9.5.0 and below emits a CSRF token in the local_available_update.php view ($token->output('do_update')) but
OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can redir
In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its
In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/t
In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were auto
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persist package-manager bootstrap metadata in the first
Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass
Cherry Studio versions 1.2.2 through 1.9.12, fixed in commit 1518530, contain a remote code execution vulnerability in S
Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary com
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and inc
When the application executes the JavaScript script embedded in the PDF within the sandbox, it fails to intercept some d
Yeoman Environment provides an API to discover, create, and run generators, and to configure where and how a generator i
In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on un
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1
OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust ve
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.7.16, the r
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-loca
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-loca
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configur
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tool
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configur
CleverTap Web SDK version 1.15.2 and earlier is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessag
Frequently Asked Questions
What is CWE-829?
CWE-829 (CWE-829) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-829?
There are 142 CVE records associated with CWE-829 in our database. Of these, 22 are critical severity, 79 are high severity, and 21 are medium severity.
How can I protect against CWE-829 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-829 using AI-powered security agents.
Detect CWE-829 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-829 vulnerabilities across your infrastructure.
Get Started