CWE-829

CWE-829 · 3 records · 3 with a public proof-of-concept

Records the NVD classes under CWE-829, highest CVSS first.

  1. CRITICAL 9.8CVE-2026-66902public PoC

    Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call. The Pluggable subclass reads credential_source.executable.command from the credentials JSON and runs it as `system($command)`, a

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 8.8CVE-2026-67623public PoC

    Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands by embedding a malicious core.fsmonitor hook in a repository's .git/config file, which is triggered when vibe invokes git status --por

    AI risk analysis on Exploit-DB.ai →

  3. UNSCOREDCVE-2026-47781public PoC

    PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-local plugins from a .pdm-plugins directory during initialization, allowing an attacker-controlled file in an untrusted repository checkout

    AI risk analysis on Exploit-DB.ai →