Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CWE-184 (不完整的黑名单) — Vulnerability Class 169

169 vulnerabilities classified as CWE-184 (不完整的黑名单). AI Chinese analysis included.

CWE-184 represents a critical input validation weakness where an application relies on a blacklist of prohibited inputs that fails to cover all malicious variations. This approach is inherently fragile because attackers can easily bypass incomplete lists using encoding techniques, alternative syntax, or edge cases not anticipated by the developer. Exploitation typically occurs when an adversary submits crafted payloads that evade the restricted set, allowing unauthorized commands, code execution, or data injection to proceed unchecked. To mitigate this risk, developers should abandon blacklisting in favor of whitelisting, which permits only explicitly verified and safe inputs. Additionally, implementing robust input sanitization and normalization processes ensures that diverse attack vectors are neutralized before processing, thereby closing the gaps left by incomplete disallowed lists and significantly strengthening the application’s security posture against injection-based threats.

MITRE CWE Description
The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are not allowed by policy or otherwise require other action to neutralize before additional processing takes place, but the list is incomplete.
Common Consequences (1)
Access Control Bypass Protection Mechanism
Attackers may be able to find other malicious inputs that were not expected by the developer, allowing them to bypass the intended protection mechanism.
Mitigations (1)
Implementation Do not rely exclusively on detecting disallowed inputs. There are too many variants to encode a character, especially when different environments are used, so there is a high likelihood of missing some variants. Only use detection of disallowed inputs as a mechanism for detecting suspicious activity. Ensure that you are using other protection mechanisms that only identify "good" input - such as …
Examples (2)
The following code attempts to stop XSS attacks by removing all occurences of "script" in an input string.
public String removeScriptTags(String input, String mask) { return input.replaceAll("script", mask); }
Bad · Java
This example takes user input, passes it through an encoding scheme, then lists the contents of the user's home directory based on the user name.
sub GetUntrustedInput { return($ARGV[0]); } sub encode { my($str) = @_; $str =~ s/\&/\&amp;/gs; $str =~ s/\"/\&quot;/gs; $str =~ s/\'/\&apos;/gs; $str =~ s/\</\&lt;/gs; $str =~ s/\>/\&gt;/gs; return($str); } sub doit { my $uname = encode(GetUntrustedInput("username")); print "<b>Welcome, $uname!</b><p>\n"; system("cd /home/$uname; /bin/ls -l"); }
Bad · Perl
' pwd
Attack
CVE ID Title CVSS Severity Published
CVE-2026-107322 OS command injection in Amazon Agent Plugins for AWS databases-on-aws — databases-on-aws 7.8 High 2026-10-08
CVE-2026-106445 Handlebars: JavaScript Injection via Own Property Check Bypass — handlebars.js 9.2 Critical 2026-10-06
CVE-2026-106442 Hydra instantiate target blacklist bypasses permit code execution — hydra 7.8 High 2026-10-06
CVE-2026-106218 TeamCity <2026.1.3 Kotlin DSL沙箱逃逸致RCE — TeamCity 8.8 High 2026-10-06
CVE-2026-105648 Ghost: Private IP Filtering Bypass via IPv6 Transition Addresses — Ghost 4.0 Medium 2026-10-05
CVE-2026-103687 rhukster dom-sanitizer SVG Sanitization DOMSanitizer.php url incomplete blacklist — dom-sanitizer 7.3 High 2026-10-01
CVE-2026-101884 OpenClaw Windows Node before 2026.7.1 Remote Code Execution via Environment Override — OpenClaw Windows Node 7.5 High 2026-09-30
CVE-2026-101882 OpenClaw Windows Node before 2026.7.1 Remote Code Execution via system.execApprovals.set — OpenClaw Windows Node 8.8 High 2026-09-30
CVE-2026-100253 TeamCity多版本Kotlin DSL沙箱逃逸致代码执行 — TeamCity 8.8 High 2026-09-30
CVE-2026-55096 SSRF via DNS-resolution gap in _validate_url_security (file download by URL) — fast-mcp-telegram 7.1 High 2026-09-28
CVE-2026-61788 @bytebase/dbhub's read-only mode does not prevent database writes — dbhub 7.4 High 2026-09-24
CVE-2026-97149 OpenStack Swift 2.38.2前TempURL头注入漏洞 — Swift 5.3 Medium 2026-09-24
CVE-2026-84714 Automation-controller: automation-controller: incomplete sanitize_jinja() regex allows jinja template injection into ad-hoc module_args, machine-credential fields, and host names, reaching ansible-core templating in the execution environment — Red Hat Ansible Automation Platform 2.5 for RHEL 8 7.1 High 2026-09-23
CVE-2026-84706 Automation-controller: automation-controller-container: automation-controller: credential type env-injector deny-list omits process-hijacking variables (bash_env/ld_preload) allowing code execution in the execution environment — Red Hat Ansible Automation Platform 2.5 for RHEL 8 7.6 High 2026-09-23
CVE-2026-75884 Awx: awx: privilege escalation to openshift namespace via pod_spec_override injection in container groups — Red Hat Ansible Automation Platform 2.4 for RHEL 8 9.1 Critical 2026-09-23
CVE-2026-61851 Chartbrew: Incomplete Read-Only Keyword Blocklist in AI runQuery Tool — chartbrew 6.5 Medium 2026-09-21
CVE-2026-93598 ArcadeDB before 26.9.1 Classpath Credential Disclosure via ResourceBundle — arcadedb 7.1 High 2026-09-18
CVE-2026-11918 IBM ContextForge MCP Gateway is affected by security filter bypass via nested payload structures — ContextForge MCP Gateway 5.4 Medium 2026-09-15
CVE-2026-57138 PraisonAI codeMode sandbox escape via Function constructor — PraisonAI 9.9 Critical 2026-09-15
CVE-2026-90808 HKUDS nanobot ExecTool shell.py ExecTool._spawn incomplete blacklist — nanobot 6.3 Medium 2026-09-14
CVE-2026-87985 Mistral AI Mistral Vibe 输入验证错误漏洞 — mistral-vibe 10.0 Critical 2026-09-11
CVE-2026-85788 Incomplete list of disallowed inputs in awslabs mysql-mcp-server — AWS Labs MySQL MCP Server 5.5 Medium 2026-09-09
CVE-2026-86199 PocketMine-MP before 5.43.1 Denial of Service via unauthenticated login — PocketMine-MP 7.5 High 2026-09-09
CVE-2026-79696 Remote Code Execution in Google ADK for Python via Incomplete Standard Library Denylist — Agent Development Kit (ADK) for Python 10.0 Critical 2026-09-09
CVE-2026-82536 Roo-Code 3.54.0 Auto-Approve Bypass via Shell Command Pipe Operator — Roo-Code 8.8 High 2026-09-08
CVE-2026-69624 Active Directory Certificate Services (AD CS) Tampering Vulnerability — Windows 10 Version 1607 6.5 Medium 2026-09-08
CVE-2026-70334 Visual Studio Code Security Feature Bypass Vulnerability — Visual Studio Code 7.8 High 2026-09-08
CVE-2026-33197 BDS Module Bypass Secure Boot Advisory — AptioV 8.7 High 2026-09-08
CVE-2026-85787 An incomplete list of disallowed inputs in the SQL validation component of Amazon awslabs postgres-mcp-server — postgres-mcp-server 6.5 Medium 2026-09-04
CVE-2026-77124 Nexus Repository 3 - Script Execution Disable Setting Not Enforced — Nexus Repository 3 7.5 High 2026-09-02

Vulnerabilities classified as CWE-184 (不完整的黑名单) represent 169 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.