ClassIncomplete

CWE-506Embedded Malicious Code

Category: other

Description

The product contains code that appears to be malicious in nature. Malicious flaws have acquired colorful names, including Trojan horse, trapdoor, timebomb, and logic-bomb. A developer might insert malicious code with the intent to subvert the security of a product or its host system at some time in the future. It generally refers to a program that performs a useful service but exploits rights of the program's user in a way the user does not intend.

Common consequences· 1

  • Confidentiality / Integrity / Availability — Execute Unauthorized Code or Commands

Potential mitigations· 1

  • [Implementation, Operation]Remove the malicious code and start an effort to ensure that no more malicious code exists. This may require a detailed review of all code, as it is possible to hide a serious attack in only one or two lines of code. These lines may be located almost anywhere in an application and may have been intentionally obfuscated by the attacker.

Related CAPEC attack patterns· 3

CAPEC-442CAPEC-448CAPEC-636

References

  1. https://cwe.mitre.org/data/definitions/506.html

Exploits (incoming)3

TypeTargetConfidenceTier
AttackPatternInfected Softwarecapec-442100%live
AttackPatternHiding Malicious Data or Code within Filescapec-636100%live
AttackPatternEmbed Virus into DLLcapec-448100%live

(incoming)21

TypeTargetConfidenceTier
VulnerabilityCVE-2025-10894cve-2025-108940%live
Vulnerabilitytj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerabilitycve-2025-300660%live
Vulnerabilityreviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerabilitycve-2025-301540%live
VulnerabilityPrettier eslint-config-prettier Embedded Malicious Code Vulnerabilitycve-2025-543130%live
VulnerabilityASUS Live Update Embedded Malicious Code Vulnerabilitycve-2025-593740%live
VulnerabilityCVE-2026-31976cve-2026-319760%live
VulnerabilityAquasecurity Trivy Embedded Malicious Code Vulnerabilitycve-2026-336340%live
VulnerabilityCVE-2026-34424cve-2026-344240%live
VulnerabilityCVE-2026-34841cve-2026-348410%live
VulnerabilityCVE-2026-44484cve-2026-444840%live
VulnerabilityTanStack Unspecified Vulnerabilitycve-2026-453210%live
VulnerabilityCVE-2026-6443cve-2026-64430%live
VulnerabilityDaemon Tools Lite Embedded Malicious Code Vulnerabilitycve-2026-83980%live
KEVEntryJustice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerabilitykev-cve-2024-49780%live
KEVEntrytj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerabilitykev-cve-2025-300660%live
KEVEntryreviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerabilitykev-cve-2025-301540%live
KEVEntryPrettier eslint-config-prettier Embedded Malicious Code Vulnerabilitykev-cve-2025-543130%live
KEVEntryASUS Live Update Embedded Malicious Code Vulnerabilitykev-cve-2025-593740%live
KEVEntryAquasecurity Trivy Embedded Malicious Code Vulnerabilitykev-cve-2026-336340%live
KEVEntryNx Console Embedded Malicious Code Vulnerabilitykev-cve-2026-480270%live
KEVEntryDaemon Tools Lite Embedded Malicious Code Vulnerabilitykev-cve-2026-83980%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CWE
Logic/Time Bomb
CWE
Trojan Horse
CWE
Improper Control of Generation of Code ('Code Injection')
CWE
Hidden Functionality
CWE
Inclusion of Functionality from Untrusted Control Sphere
CWE
Use of Potentially Dangerous Function
Sourced from MITRE CWE 4.20. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.