CWE-1116Base

Inaccurate Source Code Comments

Incomplete in the CWE catalog · 1 CVE mapped

1
CVEs mapped
6.3
Median CVSS
What it is

The source code contains comments that do not accurately

describe or explain aspects of the portion of the code with which the comment is

associated.

Recent examples
6.3cvss
CVE-2025-47271

OZI-Project/ozi-publish Code Injection vulnerability

The OZI action is a GitHub Action that publishes releases to PyPI and mirror releases, signature bundles, and provenance in a tagged release. In versions 1.13.2 through 1.13.5, potentially untrusted data flows into PR creation logic. A malicious actor could construct a branch name that injects arbitrary code. This is patched in 1.13.6. As a workaround, one may downgrade to a version prior to 1.13.2.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-1116
Abstraction
Base
Structure
Simple
Status
Incomplete
References (1)