VulnSea

CWE-829

CVEs classified under CWE-829, newest first.

61 CVEsRSS

CVE-2026-59864Critical
1mo ago

Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions

Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions

MidnightMicrosoft · Microsoft.OpenApi.KiotaEPSS 1.3%via GHSA
CVE-2026-59867High· 7.1
1mo ago

Microsoft Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref

Microsoft Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref

TwilightMicrosoft · Microsoft.OpenApi.KiotaEPSS 2.4%via GHSA
CVE-2026-59863High
1mo ago

Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF

Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF

TwilightMicrosoft · Microsoft.OpenApi.KiotaEPSS 1.4%via GHSA
CVE-2026-59865Critical
1mo ago

Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`

Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`

MidnightMicrosoft · Microsoft.OpenApi.KiotaEPSS 4.4%via GHSA
GHSA-p5rm-jg5c-8c77Medium
1mo ago

Microsoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass)

Microsoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass)

SunlitMicrosoft · Microsoft.OpenApi.Kiotavia GHSA
CVE-2026-16085Medium· 5.3
2mo ago

A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9

A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. Affected is the function NewContextBuilder of the file pkg/agent/context.go. Such manipulation leads to inclusion of functionality from untrusted control sphere. …

SunlitEPSS 0.16%via NVD
CVE-2026-62222High· 7.8
2mo ago

OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted workspace plugins

OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted workspace plugins. Attackers with lower-trust caller access or control over configured input paths can execute or persist actions …

TwilightEPSS 0.18%via NVD
CVE-2026-57102High· 8.8
2mo ago

Visual Studio Code Security Feature Bypass Vulnerability

Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

TwilightMicrosoft · Visual Studio CodeEPSS 0.82%via CVEORG
CVE-2026-15519Medium· 5.0
2mo ago

A vulnerability was found in usestrix strix up to 1.0.2

A vulnerability was found in usestrix strix up to 1.0.2. This affects an unknown function of the file system_prompt.jinja of the component PyPI Handler. Performing a manipulation results in inclusion of functionality from untrusted contr…

SunlitEPSS 0.35%via NVD
CVE-2026-53810High· 8.8
2mo ago

OpenClaw's marketplace runtime extension metadata could point at unscanned payloads

OpenClaw's marketplace runtime extension metadata could point at unscanned payloads

Twilightopenclaw · openclawEPSS 0.42%via GHSA
CVE-2026-55487High· 7.5
2mo ago

pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle

pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle

Twilightpnpm · pnpmEPSS 0.18%via GHSA
CVE-2026-55697High· 7.5
2mo ago

pnpm: Repository-controlled configDependencies can select a pacquet native install engine

pnpm: Repository-controlled configDependencies can select a pacquet native install engine

Twilightpnpm · pnpmEPSS 0.19%via GHSA
CVE-2026-55698High· 8.8
2mo ago

pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes

pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes

Twilightpnpm · pnpmEPSS 0.30%via GHSA
CVE-2026-50195Medium
3mo ago

containerd: CRI checkpoint import allows local image tag poisoning

containerd: CRI checkpoint import allows local image tag poisoning

Sunlitcontainerd · github.com/containerd/containerd/v2EPSS 0.30%via GHSA
CVE-2026-44688High
3mo ago

[Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat

[Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat

Twilighttheia · @theia/ai-chat-uiEPSS 0.51%via GHSA
CVE-2026-44691High
3mo ago

[Eclipse Theia] Arbitrary Command Execution via Untrusted Workspace Task Definitions

[Eclipse Theia] Arbitrary Command Execution via Untrusted Workspace Task Definitions

Twilighttheia · @theia/debugEPSS 0.41%via GHSA
CVE-2026-46580High
3mo ago

[Eclipse Theia] Indirect Prompt Injection via Auto-Loaded Workspace Prompt Template Files in AI Chat

[Eclipse Theia] Indirect Prompt Injection via Auto-Loaded Workspace Prompt Template Files in AI Chat

Twilighttheia · @theia/ai-chat-uiEPSS 0.51%via GHSA
CVE-2026-54325Medium· 4.4
3mo ago

Pi Agent: Pi loads project-local extensions without approval

Pi Agent: Pi loads project-local extensions without approval

Sunlitearendil-works · @earendil-works/pi-coding-agentEPSS 0.17%via GHSA
CVE-2026-46529High· 7.8PoC
3mo ago

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execut…

MidnightEPSS 0.53%via NVD
CVE-2026-5843High· 8.2PoC
4mo ago

The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the model_file configuration field in config.json

The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the model_file configuration field in config.json. When a mod…

Midnightdocker · docker_desktopEPSS 0.22%via NVD
CVE-2026-5817High· 8.2PoC
4mo ago

The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing

The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing. This causes transformers.AutoTokenizer.from_pretrained() to import a…

Midnightdocker · docker_desktopEPSS 0.22%via NVD
CVE-2026-43999Critical· 9.9
4mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, NodeVM's builtin allowlist can be bypassed when the module builtin is allowed (including via the '*' wildcard). The module builtin exposes Node's Module._load(), which loads …

Midnightvm2_project · vm2EPSS 0.97%via NVD
CVE-2026-43003High· 8.0
4mo ago

An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0

An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a mal…

Twilightopenstack · ironic_python_agentEPSS 0.98%via NVD
CVE-2026-1342High· 8.5
5mo ago

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a…

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a…

Twilightibm · security_verify_accessEPSS 0.18%via NVD
CVE-2026-34442Medium· 5.4
5mo ago

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, host header manipulation in FreeScout version (http://localhost:8080/system/status) allows an attacker to inject an arbitrary do…

Sunlitfreescout · freescoutEPSS 0.22%via NVD
CVE-2026-32920High· 8.4
5mo ago

OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust verification, allowing arbitrary code execution

OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust verification, allowing arbitrary code execution. Attackers can execute malicious code by including crafted workspace pl…

Twilightopenclaw · openclawEPSS 0.33%via NVD
CVE-2025-70974Critical· 10.0
8mo ago

Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain public methods of that class

Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain public methods of that class. Depending on the behavior of …

MidnightEPSS 0.77%via NVD
CVE-2021-41841High· 8.2
4y ago

An issue was discovered in AhciBusDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O

An issue was discovered in AhciBusDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that allows an attacker to access the System Management Mode and execute arbitrary code. This occurs because of Inclusion of…

Twilightinsyde · insydeh2oEPSS 0.30%via NVD
CVE-2021-33626High· 7.8
4y ago

A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer(QWORD values for CommBuffer)

A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer(QWORD values for CommBuffer). This can be used by an attacker to corru…

Twilightinsyde · insydeh2oEPSS 0.31%via NVD
CVE-2021-26272Medium· 6.5
5y ago

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).

Sunlitckeditor · ckeditorEPSS 2.2%via NVD
CWE-829 vulnerabilities (CVEs) — page 2 · VulnSea