Skip to main content

Threats Tagged 'cwe-184'

View all threats tagged with 'cwe-184'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-184

Threats Tagged 'cwe-184'

Click on any threat for detailed analysis and mitigation recommendations

MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to 0.22.1, @nuxtjs/mdc uses parseMarkdown with allowDangerousHtml enabled by default and relies on validateProps, validateProp, and unsafeLinkPrefix to remove executable URLs from untrusted Markdown. validateProp checks only attributes named href or src, allowing an SVG xlink:href value represented as xLinkHref to retain a javascript: URL that executes in the page origin when selected. The data:text/html denylist entries are also compared against url.protocol, which is only data:, so an iframe src containing data:text/html survives sanitization and executes in an opaque origin when loaded. Plain href javascript: URLs, srcdoc, object, script, and base elements are already blocked, making these two paths specific sibling gaps in the sanitizer. This issue is fixed in version 0.22.1.

Join the discussion

CVE-2026-11918 is a medium severity vulnerability in IBM ContextForge MCP Gateway versions up to 1.0.4. It involves an incomplete recursive inspection of nested payload content, allowing an authenticated user to bypass protection mechanisms. The vulnerability is identified as CWE-184, relating to an incomplete list of disallowed inputs. No known exploits are reported in the wild, and no official patch information is provided.

Join the discussion

PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, codeMode in src/praisonai-ts/src/tools/builtins/code-mode.ts executes untrusted JavaScript with new Function() inside with(sandbox) and relies on a small source-code blocklist plus shadowed process and require properties. Code can use ({}).constructor.constructor to recover the real Function constructor, obtain process and process.mainModule.require, and reach host filesystem and subprocess APIs despite the advertised sandbox. Attackers who control codeMode input can read secrets, modify files, execute commands, or exhaust the host process. This issue is fixed in version 1.7.2.

Join the discussion

An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using ANSI-C quoted arguments. These arguments are not properly inspected, enabling a crafted allowlisted command to execute arbitrary code on the user's system without approval.

Join the discussion

CVE-2026-87911 is a critical OS command injection vulnerability in AWS Labs postgres MCP Server versions before 1.1.7. It allows an unauthenticated attacker to execute arbitrary operating system commands on the host of a self-managed PostgreSQL server by exploiting the read-only enforcement of the SQL validation component via a crafted COPY ... TO PROGRAM statement. The issue is fixed in version 1.1.7 and later.

Join the discussion

Incomplete list of disallowed inputs in the mutable SQL detector component in Amazon awslabs mysql-mcp-server might allow context-dependent actors to bypass the read-only enforcement gate and reach file-read and file-write SQL sinks via SQL inline comments that the regex engine does not treat as whitespace. To remediate this issue, users should upgrade to version 1.0.23.

Join the discussion

A code injection vulnerability exists in the adk web component of Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0. This vulnerability affects Python (OSS), Cloud Run, and GKE environments where pytest is installed. An unauthenticated remote attacker can exploit this flaw by using a crafted test session replay to execute arbitrary code. The vulnerability is classified as critical due to its potential impact and ease of exploitation. No patch or remediation guidance is currently provided. There are no known exploits in the wild at this time.

Join the discussion

Incomplete list of disallowed inputs in Active Directory Certificate Services (AD CS) allows an authorized attacker to perform tampering over a network.

Join the discussion

Incomplete list of disallowed inputs in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

Join the discussion

AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause the “Incomplete List of Disallowed Inputs” by local access. Successful exploitation of this vulnerability may lead to arbitrary code execution and impact system Confidentiality, Integrity, and Availability.

Join the discussion

Showing 1 to 10 of 82 results

Filters:Tag: cwe-184
Page 1 of 9
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses