CVEbaza.plSłownik CWECWE-506
Common Weakness Enumeration

CWE-506

Embedded Malicious Code

Kategoria: ClassCVE: 100
Opis

Produkt zawiera kod, który ma pozory być złośliwy. Taki kod może być umyślnie wbudowany w celu spowodowania szkód lub nieautoryzowanego dostępu do systemu.

Description (EN)

The product contains code that appears to be malicious in nature.

Podatności CVE z CWE-506 (100)
10.0
CVSS
CRITICAL
CVE-2026-46412

W dniu 2026-05-11 atakujący przy użyciu skompromitowanego tokenu publikacji npm opublikował 18 złośliwych wersji pakietu @beproduct/nestjs-auth (0.1.2–0.1.19). Pakiet zawierał backdoor w skrypcie postinstall, który aktywnie wykradał dane uwierzytelniające z zainfekowanego środowiska.

pub. 2026-07-20
10.0
CVSS
CRITICAL
CVE-2026-28353

Wersja 1.8.12 rozszerzenia Trivy Vulnerability Scanner dla VS Code, dystrybuowana przez marketplace OpenVSX, zawierała złośliwy kod. Kod ten był zaprojektowany w celu wykradania wrażliwych informacji przy wykorzystaniu lokalnego agenta AI.

pub. 2026-03-05
10.0
CVSS
CRITICAL
CVE-2024-3094

W oficjalnych archiwach źródłowych biblioteki xz, począwszy od wersji 5.6.0, odkryto złośliwy kod wprowadzony do procesu budowania biblioteki liblzma. Zagrożenie ma charakter ataku na łańcuch dostaw (supply chain attack) i dotyczy każdego oprogramowania linkowanego z podatną biblioteką.

pub. 2024-03-29
9.8
CVSS
CRITICAL
CVE-2026-77649

The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.

pub. 2026-08-21
9.8
CVSS
CRITICAL
CVE-2026-77650

The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.

pub. 2026-08-21
9.8
CVSS
CRITICAL
CVE-2026-77651

The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.

pub. 2026-08-21
9.8
CVSS
CRITICAL
CVE-2026-18072

Wtyczka Advanced Responsive Video Embedder w wersji 10.8.7 dla WordPress zawiera celowo osadzony backdoor (CWE-506), który pozwala nieuwierzytelnionemu atakującemu na pełne przejęcie uprawnień administratora witryny. Podatność jest krytyczna, ponieważ nie wymaga żadnych poświadczeń ani interakcji użytkownika.

pub. 2026-07-29
9.8
CVSS
CRITICAL
CVE-2026-6443

Wszystkie wtyczki WordPress sprzedawane przez Essentialplugin zawierają celowo wstrzyknięty backdoor, wprowadzony przez złośliwego aktora, który przejął kontrolę nad tymi wtyczkami. Umożliwia to atakującemu trwały dostęp do zainfekowanych witryn oraz wstrzykiwanie spamu.

pub. 2026-04-17
9.8
CVSS
CRITICAL
CVE-2026-34841

Pakiet Bruno (open source IDE do testowania API) był podatny na atak na łańcuch dostaw polegający na wykorzystaniu skompromitowanego pakietu npm axios, który wprowadzał ukrytą zależność instalującą wieloplatformowego trojana zdalnego dostępu (RAT). Zagrożeni są użytkownicy @usebruno/cli, którzy wykonali npm install w wąskim oknie czasowym 31 marca 2026 roku.

pub. 2026-04-06
9.8
CVSS
CRITICAL
CVE-2017-16128

Pakiet npm-script-demo zawierał złośliwy kod nawiązujący połączenie do serwera command and control (C2). Pakiet został usunięty z rejestru npm, jednak systemy które go wcześniej zainstalowały mogą być nadal zagrożone.

pub. 2018-06-07
9.6
CVSS
CRITICAL
CVE-2026-45758

11 maja 2026 roku atakujący opublikował na PyPI złośliwą wersję pakietu `guardrails-ai` (0.10.1) zawierającą osadzony szkodliwy kod (CWE-506). Każdy użytkownik, który zainstalował tę wersję w dniu publikacji, mógł narazić swoje poświadczenia i środowisko na kompromitację.

pub. 2026-06-05
9.6
CVSS
CRITICAL
CVE-2026-45321

W dniu 2026-05-11 opublikowano 84 złośliwe wersje 42 pakietów @tanstack/* w rejestrze npm, wykorzystując skompromitowany token OIDC do uwierzytelnionych publikacji pod zaufaną tożsamością. Pakiety zawierały malware kradnące dane uwierzytelniające, co stanowi poważne zagrożenie dla wszystkich projektów korzystających z dotkniętych zależności.

pub. 2026-05-12🚩 CISA KEV⚡ EXPLOIT
9.6
CVSS
CRITICAL
CVE-2025-10894

Do pakietu Nx (system budowania projektów) oraz powiązanych wtyczek opublikowanych w rejestrze npm został wstrzyknięty złośliwy kod w ramach ataku supply-chain. Skompromitowane wersje pakietu zbierają dane uwierzytelniające z systemu plików użytkownika i przesyłają je na zewnętrzne repozytoria GitHub.

pub. 2025-09-24
9.4
CVSS
CRITICAL
CVE-2026-33634

19 marca 2026 r. atakujący, używając skradzionych danych uwierzytelniających, opublikował złośliwą wersję Trivy v0.69.4 oraz podmienił dziesiątki tagów wersji w repozytoriach `aquasecurity/trivy-action` i `aquasecurity/setup-trivy` na malware kradnący poświadczenia. Jest to kontynuacja ataku na łańcuch dostaw zapoczątkowanego pod koniec lutego 2026 r., co czyni go wyjątkowo niebezpiecznym dla organizacji korzystających z Trivy w potokach CI/CD.

pub. 2026-03-23🚩 CISA KEV⚡ EXPLOIT
9.3
CVSS
CRITICAL
CVE-2026-74232

Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, AP522 firmware 1.0.0.2.014, AP7628 and HC5661A firmware 3.0.0.4.380, APG721B firmware 19.0809, HK300 firmware 1.0.0.2.032, and MAP-N10 firmware 1.0.0.2.044 ship a backdoor command-and-control implant (yunmgrd) reachable over an unauthenticated cleartext UDP channel to a hardcoded C2 server. A remote unauthenticated attacker on the network path can hijack the channel and execute arbitrary commands as root. The attacker can also modify DNS entries, exfiltrate PPPoE credentials, and open reverse SSH tunnels.

pub. 2026-08-27
9.3
CVSS
CRITICAL
CVE-2026-73532

Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php, that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.

pub. 2026-08-13
9.3
CVSS
CRITICAL
CVE-2026-73533

Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.

pub. 2026-08-13
9.3
CVSS
CRITICAL
CVE-2026-48158

use-context-selector is a React useContextSelector hook in userland Between 2026-05-18 15:57:18 and 2026-05-19 15:24:34, the default branch contained malicious commits 9d8481a513b7b0d1c0941b220c69b25de748641b through 6f2dae054ca014068bdbbb4db96006424d674124 that executed remote attacker-controlled code on developer machines during `npm install`. The commits were removed by force-push, but local clones, forks, and direct-SHA URLs may still contain them, and `npm install` against an affected checkout will still execute the code today. The package was not published to npm. `src/install.js` was added and wired into the `postinstall` script. It fetched a JavaScript payload from an attacker-controlled HTTPS endpoint (configurable via an environment variable), disabled TLS verification, and evaluated the response as code with `require` available. Execution was deliberately skipped on CI and cloud/serverless environments, targeting developer workstations. The second-stage payload was attacker-hosted and cannot be reconstructed. Assume full compromise of anything reachable from a Node process with the user's permissions. Those who ran `npm install` against an affected checkout on a developer machine on or after 2026-05-18 15:57:18 should treat the machine as compromised, rotate every credential the machine could reach, audit account activity** since 2026-05-18 15:57:18, and clean local clones.

pub. 2026-08-10
9.3
CVSS
CRITICAL
CVE-2026-48159

use-reducer-async is a React useReducer with async actions. Between 2026-05-18 16:29:52 and 2026-05-19 15:26:07, the default branch contained malicious commits da72edbde5705efcec6c62e0a3dcb73687b78dc8 through df07d5711458d8b46e11dd7afaaa21e88cafabfb that executed remote attacker-controlled code on developer machines during `npm install`. The commits were removed by force-push, but local clones, forks, and direct-SHA URLs may still contain them, and `npm install` against an affected checkout will still execute the code today. The package was not published to npm. `src/install.js` was added and wired into the `postinstall` script. It fetched a JavaScript payload from an attacker-controlled HTTPS endpoint (configurable via an environment variable), disabled TLS verification, and evaluated the response as code with `require` available. Execution was deliberately skipped on CI and cloud/serverless environments, targeting developer workstations. The second-stage payload was attacker-hosted and cannot be reconstructed. Assume full compromise of anything reachable from a Node process with the user's permissions. Those who ran `npm install` against an affected checkout on a developer machine on or after 2026-05-18 16:29:52 should treat the machine as compromised, rotate every credential the machine could reach, audit account activity since 2026-05-18 16:29:52, and clean local clones.

pub. 2026-08-10
9.3
CVSS
CRITICAL
CVE-2026-48160

react-tracked provides state usage tracking with Proxies. Between 2026-05-18 19:26:36 and 2026-05-19 15:22:45, the default branch contained malicious commits 6978272a7d6ca02225cb747ea69f427512e33699 through 949f1a3d6bb1ff7d1a0dec892afd773e742627e8 that executed remote attacker-controlled code on developer machines during `npm install`. The commits were removed by force-push, but local clones, forks, and direct-SHA URLs may still contain them, and `npm install` against an affected checkout will still execute the code today. The package was not published to npm. `src/install.js` was added and wired into the `postinstall` script. It fetched a JavaScript payload from an attacker-controlled HTTPS endpoint (configurable via an environment variable), disabled TLS verification, and evaluated the response as code with `require` available. Execution was deliberately skipped on CI and cloud/serverless environments, targeting developer workstations. The second-stage payload was attacker-hosted and cannot be reconstructed. Assume full compromise of anything reachable from a Node process with the user's permissions. Those who ran `npm install` against an affected checkout on a developer machine on or after 2026-05-18 19:26:36 should treat the machine as compromised, rotate every credential the machine could reach, audit account activity** since 2026-05-18 19:26:36, and clean local clones.

pub. 2026-08-10
Pokazano 20 z 100 podatności
Informacje
ID: CWE-506
Typ: Class
Podatności: 100
MITRE CWE ↗
← Słownik CWE