CWE-914Base

Improper Control of Dynamically-Identified Variables

Incomplete in the CWE catalog · 7 CVEs mapped

7
CVEs mapped
8.0
Median CVSS
What it is

The product does not properly restrict reading from or writing to dynamically-identified variables.

Recent examples
10.0cvss
CVE-2026-44006

CVE-2026-44006 - CRITICAL Severity Vulnerability

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which can be used to get arbitrary prototypes. This vulnerability is fixed in 3.11.0.

CRITICALno explanation yet
1%
epss
6.5cvss
CVE-2026-35173

Chyrp Lite has an IDOR via Mass Assignment in Post Model

Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, an IDOR / Mass Assignment issue exists in the Post model that allows authenticated users with post editing permissions (Edit Post, Edit Draft, Edit Own Post, Edit Own Draft) to modify posts they do not own and do not have permission to edit. By passing internal class properties such as id into the post_attributes payload, an attacker can alter the object being instantiated. As a result, further actions are performed on another user’s post rather than the attacker’s own post, effectively enabling post takeover. This vulnerability is fixed in 2026.01.

MEDIUMno explanation yet
0%
epss
5.3cvss
CVE-2025-14085

youlaitech youlai-mall orders improper control of dynamically-identified variables

A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. This impacts an unknown function of the file /app-api/v1/orders/. The manipulation of the argument orderId leads to improper control of dynamically-identified variables. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-914
Abstraction
Base
Structure
Simple
Status
Incomplete