Skip to main content

Threats Tagged 'cwe-913'

View all threats tagged with 'cwe-913'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-913

Threats Tagged 'cwe-913'

Click on any threat for detailed analysis and mitigation recommendations

A vulnerability in Sentry Seer allows attacker-controlled input submitted via a public telemetry endpoint to be executed in a privileged coding-agent environment. This occurs when Seer is configured to automatically hand off issues to a coding agent for remediation. Malicious event data can propagate through Seer's analysis pipeline and cause the coding agent to execute attacker-controlled code before any human review. No vendor patch is currently available.

Join the discussion

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code on the application server due to improper validation of JNDI names in the Resource Adapter Installation Verification Test application.

Join the discussion

CVE-2026-41870 is a high severity vulnerability in Apache Nutch versions 1.11 through 1.22 affecting the Nutch REST API. It involves missing authorization controls, leading to risks such as code injection, unsafe reflection, and improper control of dynamically managed code resources. The vulnerability allows unauthorized users with limited privileges to potentially execute harmful actions. Apache Nutch 1.23 removes the vulnerable Nutch Server component, mitigating this issue. Users unable to upgrade should restrict access to trusted users only.

Join the discussion

Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a client with privileges to upload a file to remote storage and create a table to execute arbitrary Java code. Users are recommended to upgrade to version 4.5.2, which fixes this issue.

Join the discussion

A vulnerability was determined in Eleveo Quality Management 9.7.0. Impacted is an unknown function of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the component Conversation Handler. This manipulation of the argument createdBy causes dynamically-determined object attributes. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

Join the discussion

CVE-2026-59283 is a critical vulnerability in the Spring Framework affecting multiple versions from 5.2.25.RELEASE and earlier through 7.0.8. It involves improper control of dynamically-managed code resources when evaluating Spring Expression Language (SpEL) expressions using SimpleEvaluationContext with the SpEL expression compiler active. This can lead to a safety guard bypass, resulting in high impact on integrity and availability.

Join the discussion

CVE-2026-48105 is a path traversal vulnerability in Basekick-Labs' Arc Enterprise time-series database prior to version 26.06.1. The Raft FSM component accepts attacker-controlled file paths without proper validation, allowing potentially unauthorized file access or manipulation. The vulnerability is fixed in version 26.06.1. Mitigations include restricting cluster network access to trusted peers, auditing manifest paths, or disabling cluster mode until patched.

Join the discussion

CVE-2026-71470 is a critical vulnerability in Red Hat Advanced Cluster Management for Kubernetes 2.11 affecting the search-v2-operator. It allows a privileged user with Custom Resource editor permissions to manipulate certain fields without proper validation, enabling them to inject arbitrary secrets or replace container images. This can lead to privilege escalation and potentially full cluster compromise due to the extensive impersonation permissions of the ServiceAccount involved. The vulnerability has a CVSS score of 9.1, indicating high severity. Red Hat has released security updates addressing this issue in later versions, notably in the 2.17 release series.

Join the discussion

CVE-2026-47698 is a critical vulnerability in the open source Node.js sandbox vm2 prior to version 3.11.6. The flaw allows sandboxed code to bypass prototype chain protections via stacked indirection through Function.prototype.call, enabling arbitrary host command execution. This is due to improper control of dynamically-managed code resources in specific vm2 modules. The issue is fixed in vm2 version 3.11.6.

Join the discussion

Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in the computed fields feature uses an AST validator that only blocks attributes starting with underscore. Python generator and frame object attributes (gi_frame, f_back, f_builtins) do NOT start with underscore, enabling a complete sandbox escape to achieve arbitrary code execution. The attack requires no authentication (JWT disabled by default) and is triggered via POST /crawl with a crafted extraction schema. This vulnerability is fixed in 0.8.7.

Join the discussion

Showing 1 to 10 of 33 results

Filters:Tag: cwe-913
Page 1 of 4
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses