Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-829

MITRE ↗

CWE-829

22
CRITICAL
79
HIGH
21
MEDIUM
137 CVEs · Page 1/3
10.0
CVE-2025-70974

Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key i

10.0
CVE-2026-1699

In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_tar

10.0
CVE-2026-44359

Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository

10.0
CVE-2026-22306

Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext trans

9.9
CVE-2026-27941

OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in Open

9.9
CVE-2026-43999

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, NodeVM's builtin allowlist can be bypassed when the modul

9.9
CVE-2026-50195

containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the

9.8
CVE-2026-0770 KEV

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This

9.8
CVE-2026-26974

Slyde is a program that creates animated presentations from XML. In versions 0.0.4 and below, Node.js automatically impo

9.8
CVE-2025-70046

An issue pertaining to CWE-829: Inclusion of Functionality from Untrusted Control Sphere was discovered in Miazzy oa-fro

9.8
CVE-2026-44484

PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introdu

9.8
CVE-2026-58116

LLaMA-Factory through 0.9.5 contains a remote code execution vulnerability that allows attackers with WebUI access to ex

9.8
CVE-2026-66902

Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated sy

9.6
CVE-2026-22208

OpenS100 (the reference implementation S-100 viewer) prior to commit 753cf29 contains a remote code execution vulnerabil

9.6
CVE-2026-43944

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From versions 3.0.6 to before

9.6
CVE-2026-44336

PraisonAI is a multi-agent teams system. Prior to version 4.6.34, PraisonAI's MCP (Model Context Protocol) server (prais

9.6
CVE-2026-5241

A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-control

9.3
CVE-2026-40154

PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI treats remotely fetched template files as trusted e

9.3
CVE-2026-40959

Luanti 5 before 5.15.2, when LuaJIT is used, allows a Lua sandbox escape via a crafted mod.

9.1
CVE-2026-40313

PraisonAI is a multi-agent teams system. In versions 4.5.139 and below, the GitHub Actions workflows are vulnerable to A

9.1
CVE-2026-40903

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can

9.0
CVE-2026-71471

A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically wit

8.8
CVE-2026-33075

FastGPT is an AI Agent building platform. In versions 4.14.8.3 and below, the fastgpt-preview-image.yml workflow is vuln

8.8
CVE-2026-6859

A flaw was found in InstructLab. The `linux_train.py` script hardcodes `trust_remote_code=True` when loading models from

8.8
CVE-2026-43569

OpenClaw before 2026.4.9 contains an authentication bypass vulnerability allowing untrusted workspace plugins to be auto

8.8
CVE-2026-43571

OpenClaw before 2026.4.10 contains a plugin trust bypass vulnerability that allows channel setup catalog lookups to reso

8.8
CVE-2026-8426

Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/prepa

8.8
CVE-2026-8428

Concrete CMS 9.5.0 and below emits a CSRF token in the local_available_update.php view ($token->output('do_update')) but

8.8
CVE-2026-53810

OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can redir

8.8
CVE-2026-44688

In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its

8.8
CVE-2026-44691

In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/t

8.8
CVE-2026-46580

In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were auto

8.8
CVE-2026-55698

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persist package-manager bootstrap metadata in the first

8.8
CVE-2026-57102

Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass

8.8
CVE-2026-40501

Cherry Studio versions 1.2.2 through 1.9.12, fixed in commit 1518530, contain a remote code execution vulnerability in S

8.8
CVE-2026-67623

Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary com

8.8
CVE-2026-18408

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary

8.6
CVE-2026-28500

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and inc

8.6
CVE-2026-12057

When the application executes the JavaScript script embedded in the PDF within the sandbox, it fails to intercept some d

8.6
CVE-2026-42089

Yeoman Environment provides an API to discover, create, and run generators, and to configure where and how a generator i

8.6
CVE-2026-65908

In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on un

8.5
CVE-2026-1342

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1

8.4
CVE-2026-32920

OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust ve

8.4
CVE-2026-43940

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.7.16, the r

8.4
CVE-2026-64804

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-loca

8.4
CVE-2026-64805

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-loca

8.4
CVE-2026-64806

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configur

8.4
CVE-2026-64808

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tool

8.4
CVE-2026-64809

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configur

8.3
CVE-2026-26862

CleverTap Web SDK version 1.15.2 and earlier is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessag

Frequently Asked Questions

What is CWE-829?

CWE-829 (CWE-829) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-829?

There are 142 CVE records associated with CWE-829 in our database. Of these, 22 are critical severity, 79 are high severity, and 21 are medium severity.

How can I protect against CWE-829 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-829 using AI-powered security agents.

Detect CWE-829 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-829 vulnerabilities across your infrastructure.

Get Started