Inclusion of Functionality from Untrusted Control Sphere vulnerability in WP Royal Royal Elementor Addons royal-elemento
The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loadin
The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and exe
Espressif Shared GitHub DangerJS is a reusable GitHub Action CI DangerJS workflow for Espressif GitHub projects. Prior t
PraisonAI is a multi-agent teams system. The v4.6.32 chokepoint refactor (which patched CVE-2026-44334 / GHSA-xcmw-grxf-
when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmars
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as p
An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes execu
A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote
vscode-spell-checker is a basic spell checker that works well with code and documents. Prior to v4.5.4, DocumentSettings
ADB Explorer is a fluent UI for ADB on Windows. Versions 0.9.26020 and below fail to validate the integrity or authentic
ADB Explorer is a fluent UI for ADB on Windows. In versions prior to Beta 0.9.26022, ADB-Explorer allows the `ManualAdbP
A DLL search order hijacking vulnerability in Thermalright TR-VISION HOME on Windows (64-bit) allows a local attacker to
Improper trust boundary enforcement in Kiro IDE before version 0.8.0 on all supported platforms might allow a remote una
Symantec Data Loss Prevention Windows Endpoint, prior to 25.1 MP1, 16.1 MP2, 16.0 RU2 HF9, 16.0 RU1 MP1 HF12, and 16.0 M
PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI automatically loads a file named tools.py from the
The Rapid7 Insight Agent (versions > 4.1.0.2) is vulnerable to a local privilege escalation attack that allows users to
OpenClaw before 2026.4.2 contains an improper trust boundary vulnerability allowing untrusted workspace channel shadows
OpenClaw before 2026.3.31 allows workspace .env files to override the OPENCLAW_BUNDLED_HOOKS_DIR environment variable, e
OpenClaw before 2026.3.31 allows workspace .env files to override the OPENCLAW_BUNDLED_PLUGINS_DIR environment variable,
An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Ba
An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backu
Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevat
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote co
Vim is an open source, command line text editor. Prior to version 9.2.0561, the Python omni-completion script in python3
OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted workspace plu
ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI, automatically loads and executes the MCP servers defined i
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via develop
PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of p
Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized
A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without
FIBARO System Home Center 5.021 contains a remote file inclusion vulnerability in the undocumented proxy API that allows
In Umbraco UmbracoForms through 8.13.16, an authenticated attacker can supply a malicious WSDL (aka Webservice) URL as a
Version 3.0.7 of the Securly Chrome Extension dynamically registers content13.min.js as a content script via chrome.scri
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Inclusion of Functionality from Untrusted Control Sph
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, the generic peer-suffix normalizer also stripped parenthesized t
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can install configDependencies declared in pnpm-workspace.y
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving d
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving d
telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service creden
Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.
Local privilege escalation in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Che
OpenClaw before 2026.3.28 contains an arbitrary code execution vulnerability in mirror mode that converts untrusted sand
OpenClaw before 2026.4.20 contains an improper environment variable validation vulnerability in MCP stdio server configu
GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3
MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path
Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.
Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker in a privileged n
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota resolved OpenAPI $ref values by
Frequently Asked Questions
What is CWE-829?
CWE-829 (CWE-829) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-829?
There are 142 CVE records associated with CWE-829 in our database. Of these, 22 are critical severity, 79 are high severity, and 21 are medium severity.
How can I protect against CWE-829 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-829 using AI-powered security agents.
Detect CWE-829 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-829 vulnerabilities across your infrastructure.
Get Started