Embedded Malicious Code (CWE-506)
CWE-506 describes a product that contains code that appears to be malicious. MITRE groups Trojan horses, trapdoors, time bombs and logic bombs under this Class. Such code may be inserted deliberately to subvert the product or its host later.
About CWE-506
The listed impact is execution of unauthorized code or commands, affecting confidentiality, integrity and availability.
Mitigations
- +Remove the malicious code once it is found.
- +Review the entire codebase for further malicious code, since an attack can hide in one or two lines anywhere.
- +Expect intentional obfuscation and include binary and generated code in the review.
Detection
MITRE cites disassembly with manual analysis, monitored execution, manual source review and origin analysis, each giving partial coverage.
CWE-506 Vulnerabilities
9 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-48027 | Compromised Nx Console version 18.95.0 | nrwl | 9.3 | 1.3% | KEV | 2026-05-27 |
| CVE-2026-45321 | Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys | @tanstack | 9.6 | 1.1% | KEV | 2026-05-12 |
| CVE-2026-8398 | Daemon Tools Lite Embedded Malicious Code Vulnerability | AVB Disc Soft | 9.8 | 1.0% | KEV | 2026-05-15 |
| CVE-2026-33634 | Trivy ecosystem supply chain briefly compromised | aquasecurity | 9.4 | 1.7% | KEV | 2026-03-23 |
| CVE-2025-54313 | Prettier eslint-config-prettier Embedded Malicious Code Vulnerability | prettier | 7.5 | 4.5% | KEV | 2025-07-19 |
| CVE-2025-59374 | ASUS Live Update Embedded Malicious Code Vulnerability | ASUS | 9.3 | 1.2% | KEV | 2025-12-17 |
| CVE-2025-30154 | Multiple Reviewdog actions were compromised during a specific time period | reviewdog | 8.6 | 2.4% | KEV | 2025-03-19 |
| CVE-2025-30066 | tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability | tj-actions | 8.6 | 72.1% | KEV | 2025-03-15 |
| CVE-2024-4978 | Malicious Code in Justice AV Solutions (JAVS) Viewer | Justice AV Solutions | 8.7 | 26.9% | KEV | 2024-05-23 |
Tool Categories That Address This Weakness
Frequently Asked Questions
What is CWE-506?→
CWE-506 is the presence of code in a product that appears malicious, such as a Trojan horse or logic bomb.
Why is remediation of CWE-506 broader than removing one function?→
MITRE notes that malicious code can be hidden in very few lines and deliberately obfuscated, so a full review for other insertions is needed.
How many exploited vulnerabilities are classified as CWE-506?→
This database lists 9 CVE records mapped to CWE-506 by their CVE Numbering Authority. 9 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 2 to known ransomware campaigns. Examples include CVE-2026-48027, CVE-2026-45321, CVE-2026-8398.
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.