Skip to main content

About CWE-506

The listed impact is execution of unauthorized code or commands, affecting confidentiality, integrity and availability.

MITRE name
Embedded Malicious Code
Abstraction
Class: a very abstract weakness, typically independent of language or technology
Status
Incomplete

Mitigations

  • +Remove the malicious code once it is found.
  • +Review the entire codebase for further malicious code, since an attack can hide in one or two lines anywhere.
  • +Expect intentional obfuscation and include binary and generated code in the review.

Detection
MITRE cites disassembly with manual analysis, monitored execution, manual source review and origin analysis, each giving partial coverage.

CWE-506 Vulnerabilities

9 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-48027
Compromised Nx Console version 18.95.0
nrwl9.31.3%KEV2026-05-27
CVE-2026-45321
Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
@tanstack9.61.1%KEV2026-05-12
CVE-2026-8398
Daemon Tools Lite Embedded Malicious Code Vulnerability
AVB Disc Soft9.81.0%KEV2026-05-15
CVE-2026-33634
Trivy ecosystem supply chain briefly compromised
aquasecurity9.41.7%KEV2026-03-23
CVE-2025-54313
Prettier eslint-config-prettier Embedded Malicious Code Vulnerability
prettier7.54.5%KEV2025-07-19
CVE-2025-59374
ASUS Live Update Embedded Malicious Code Vulnerability
ASUS9.31.2%KEV2025-12-17
CVE-2025-30154
Multiple Reviewdog actions were compromised during a specific time period
reviewdog8.62.4%KEV2025-03-19
CVE-2025-30066
tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability
tj-actions8.672.1%KEV2025-03-15
CVE-2024-4978
Malicious Code in Justice AV Solutions (JAVS) Viewer
Justice AV Solutions8.726.9%KEV2024-05-23

Frequently Asked Questions

What is CWE-506?→

CWE-506 is the presence of code in a product that appears malicious, such as a Trojan horse or logic bomb.

Why is remediation of CWE-506 broader than removing one function?→

MITRE notes that malicious code can be hidden in very few lines and deliberately obfuscated, so a full review for other insertions is needed.

How many exploited vulnerabilities are classified as CWE-506?→

This database lists 9 CVE records mapped to CWE-506 by their CVE Numbering Authority. 9 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 2 to known ransomware campaigns. Examples include CVE-2026-48027, CVE-2026-45321, CVE-2026-8398.

Sources

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.