On this page
CWE-829: Inclusion of Functionality from Untrusted Control Sphere
Weakness Summary
The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
- Canonical source: MITRE CWE-829 (opens in a new tab)
- Published Atomicorp CVE observations: 13
- Distinct affected products in those observations: 11
- Active Atomicorp rules associated with this weakness: 20
Atomicorp Research Context
Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.
The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.
A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.
Selected Published CVE Observations
| CVE | Vulnerability | Product | Atomicorp finding | Observed rules |
|---|---|---|---|---|
| CVE-2018-17246 | Kibana - Local File Inclusion | kibana | Attack Blocked by Atomicorp | 340007 , 344360 , 347009 , 390709 |
| CVE-2026-0770 | Langflow < 1.3.0 - Remote Code Execution via validate_code() exec() | langflow | Attack Blocked by Atomicorp | 344360 , 344370 |
| CVE-2026-45272 | MyBooks: Remote Code Execution via SOCIAL_AUTH Key Name Injection in Python Config File | talebook | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2024-8252 | WordPress Clean Login <= 1.14.5 Authenticated (Contributor+) - Local File Inclusion | clean login | Attack Blocked by Atomicorp | 344360 |
| CVE-2026-45711 | Mailpit: Path traversal & arbitrary file write in mailpit dump –http via attacker-controlled message IDs | mailpit | Attack Blocked by Atomicorp | 340007 , 344360 , 390709 |
| CVE-2017-14095 | Trend Micro Smart Protection Server - Session Hijacking / Log File Disclosure / Remote Command Execution / Cron Job Injection / Local File Inclusion / Stored Cross-Site Scripting / Improper Access Control | smart protection server | Attack Blocked by Atomicorp | 330791 , 340007 , 340152 |
| CVE-2026-47398 | PraisonAI: Arbitrary code execution via unguarded spec.loader.exec_module in agents_generator.py - sibling of CVE-20 | PraisonAI | Attack Blocked by Atomicorp | 340014 , 340023 , 340029 , 344360 , 344361 , 344363 , 344364 , 344366 , 344370 , 393655 |
| CVE-2022-25485 | Cuppa CMS v1.0 - Local File Inclusion | cuppacms | Attack Blocked by Atomicorp | 340007 , 344360 , 390709 |
| CVE-2022-25486 | Cuppa CMS v1.0 - Local File Inclusion | cuppacms | Attack Blocked by Atomicorp | 340007 , 344360 , 390709 |
| CVE-2018-7422 | WordPress Site Editor <=1.1.1 - Local File Inclusion | site editor | Attack Blocked by Atomicorp | 336461 , 344360 , 347009 , 381206 , 390709 , 393771 |
| CVE-2021-41569 | SAS/Internet 9.4 1520 - Local File Inclusion | sas/intrnet | Attack Blocked by Atomicorp | 344360 , 347009 |
| CVE-2022-34121 | CuppaCMS v1.0 - Local File Inclusion | cuppacms | Attack Blocked by Atomicorp | 340007 , 344360 , 390709 |
| CVE-2026-34442 | FreeScout: Host Header Injection Leading to External Resource Loading and Open Redirect in FreeScout | freescout | Attack Blocked by Atomicorp | 340165 , 344365 |
Associated Atomicorp WAF Rules
| Rule | Status | Behavior |
|---|---|---|
| 330791 | Active | disruptive (deny) |
| 336461 | Active | disruptive (deny) |
| 340007 | Active | disruptive (deny) |
| 340014 | Active | disruptive (deny) |
| 340023 | Active | disruptive (deny) |
| 340029 | Active | disruptive (deny) |
| 340152 | Active | disruptive (deny) |
| 340165 | Active | disruptive (deny) |
| 344360 | Active | disruptive (deny) |
| 344361 | Active | disruptive (deny) |
| 344363 | Active | disruptive (deny) |
| 344364 | Active | disruptive (deny) |
| 344365 | Active | disruptive (deny) |
| 344366 | Active | disruptive (deny) |
| 344370 | Active | disruptive (deny) |
| 347009 | Active | disruptive (deny) |
| 381206 | Active | disruptive (deny) |
| 390709 | Active | disruptive (deny) |
| 393655 | Active | disruptive (deny) |
| 393771 | Active | disruptive (deny) |
Related MITRE CAPEC Context
MITRE associates this CWE with the following attack-pattern entries. These taxonomy relationships are context, not Atomicorp coverage claims:
CAPEC-175 (opens in a new tab) , CAPEC-201 (opens in a new tab) , CAPEC-228 (opens in a new tab) , CAPEC-251 (opens in a new tab) , CAPEC-252 (opens in a new tab) , CAPEC-253 (opens in a new tab) , CAPEC-263 (opens in a new tab) , CAPEC-538 (opens in a new tab) , CAPEC-549 (opens in a new tab) , CAPEC-640 (opens in a new tab) , CAPEC-660 (opens in a new tab) , CAPEC-695 (opens in a new tab) , CAPEC-698 (opens in a new tab)