Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.22.
In iTerm2 through 3.6.9, displaying a .txt file can cause code execution via DCS 2000p and OSC 135 data, if the working
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.
Kdenlive before 26.04.1 allows dangerous proxy parameters when an attacker-controlled project file is used.
In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP r
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information
NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause improper control of code generation
Sony BRAVIA Digital Signage 1.7.8 contains a remote file inclusion vulnerability that allows attackers to inject arbitra
OpenClaw version 2026.2.22 prior to 2026.2.23 contains an arbitrary code execution vulnerability in shell-env that allow
Inclusion of Functionality from Untrusted Control Sphere vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex
Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the mailpit dump --http <base-url> <ou
css_parser is a Ruby CSS parser. Prior to 2.1.0 and 1.22.0, the CSS Parser gem does not validate HTTPS connections, allo
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, host header
A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. Affected is the function NewContextBuilder of
A vulnerability was found in usestrix strix up to 1.0.2. This affects an unknown function of the file system_prompt.jinj
Wazuh provisioning scripts and Dockerfiles contain an insecure transport vulnerability where curl is invoked with the -k
Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comme
Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external sites within the Ma
Pi is a minimal terminal coding harness. Pi before 0.79.0 loaded project-local configuration and resources from a reposi
GitHub CLI (gh) is GitHub’s official command line tool. From 2.10.0 through 2.95.0, connecting to a malicious Codespace
HCL Aftermarket DPC is affected by Cross Domain Script Include vulnerability where an attacker using external scripts ca
Improper handling of untrusted remote references in Snowflake CLI versions prior to 3.19 allowed server-side request for
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importin
Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that allows a user to gain SYSTEM level contr
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, the r
In Duck Site before version 1.0.1, the repository has a deploy workflow that runs after the build workflow completes. Th
Cursor is a code editor built for programming with AI. In versions prior to 3.0.0, the Cursor Desktop could execute work
FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, ar
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota plugin add` and `kiota plugin g
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota info` read x-ms-kiota-info.lang
PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-
Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimbal
In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integration without requiri
The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats th
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who controls or tampers wi
Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim co
MyBooks is an enhanced and easy-to-use personal ebook management web server also known as Talebook. In 3.41.2 and earlie
Sandbox escape in the JavaScript Task feature of Google Cloud Application Integration allows an actor to execute arbitra
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Arbitrary Conte
Claude Code is an agentic coding tool. Prior to Claude Code version 1.0.39, when using Claude Code with Yarn versions 2.
Inclusion of Functionality from Untrusted Control Sphere, Improper Control of Filename for Include/Require Statement in
FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to version 1.7.1, an extension execution pa
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
Folo organizes feeds content into one timeline. Using pull_request_target on .github/workflows/auto-fix-lint-format-comm
The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulne
Python JSON Logger is a JSON Formatter for Python Logging. Between 30 December 2024 and 4 March 2025 Python JSON Logger
A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated, remote attacker to persuade
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary
Cursor is a code editor built for programming with AI. In versions 1.7 and below, automatic loading of project-specific
Frequently Asked Questions
What is CWE-829?
CWE-829 (CWE-829) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-829?
There are 345 CVE records associated with CWE-829 in our database. Of these, 49 are critical severity, 178 are high severity, and 63 are medium severity.
How can I protect against CWE-829 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-829 using AI-powered security agents.
Detect CWE-829 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-829 vulnerabilities across your infrastructure.
Get Started