VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 127 of 192
  • CVE-2026-36365HigMay 4, 2026
    risk 0.44cvss 7.8epss 0.00

    An issue in Lymphatus caesium-image-compressor All versions up to and including commit 02da2c6 allows a local attacker to execute arbitrary code via the shutdownMachine and putMachineToSleep functions in PostCompressionActions.cpp

  • CVE-2026-21709MedApr 17, 2026
    risk 0.44cvss 6.7epss 0.00

    A vulnerability allowing a local attacker with administrator privileges to bypass Windows Driver Signature Enforcement.

  • CVE-2026-23779MedApr 17, 2026
    risk 0.44cvss 6.7epss 0.01

    Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain a command injection vulnerability. A high…

  • CVE-2026-27001HigFeb 20, 2026
    risk 0.44cvss 7.8epss 0.00

    OpenClaw is a personal AI assistant. Prior to version 2026.2.15, OpenClaw embedded the current working directory (workspace path) into the agent system prompt without sanitization. If an attacker can cause OpenClaw to run inside a directory whose name contains control/format…

  • CVE-2026-21522MedFeb 10, 2026
    risk 0.44cvss 6.7epss 0.00

    Improper neutralization of special elements used in a command ('command injection') in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.

  • CVE-2026-24905HigJan 29, 2026
    risk 0.44cvss 7.8epss 0.01

    Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. The `ig` binary provides a subcommand for image building, used to generate custom gadget OCI images. A part of this functionality is…

  • CVE-2025-64993MedDec 11, 2025
    risk 0.44cvss 6.8epss 0.01

    A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-ConfigMgrConsoleExtensions instructions. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation…

  • CVE-2025-64992MedDec 11, 2025
    risk 0.44cvss 6.8epss 0.01

    A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-PauseNomadJobQueue instruction prior V25. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands.…

  • CVE-2025-64991MedDec 11, 2025
    risk 0.44cvss 6.8epss 0.01

    A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-PatchInsights-Deploy instruction prior V15. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands.…

  • CVE-2025-63674MedNov 24, 2025
    risk 0.44cvss 6.8epss 0.00

    An issue in Blurams Lumi Security Camera (A31C) v23.1227.472.2926 allows local physical attackers to execute arbitrary code via overriding the bootloader on the SD card.

  • CVE-2025-62214MedNov 11, 2025
    risk 0.44cvss 6.7epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code locally.

  • CVE-2025-58178HigSep 2, 2025
    risk 0.44cvss 7.8epss 0.01

    SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. In versions 4 to 5.3.0, a command injection vulnerability was discovered in the SonarQube Scan GitHub Action that allows untrusted input arguments to be processed…

  • CVE-2025-29517MedAug 25, 2025
    risk 0.44cvss 6.8epss 0.02

    D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the traceroute6 function.

  • CVE-2025-7083MedJul 6, 2025
    risk 0.44cvss 6.3epss 0.41

    A vulnerability was found in Belkin F9K1122 1.00.33. It has been classified as critical. This affects the function mp of the file /goform/mp of the component webs. The manipulation of the argument command leads to os command injection. It is possible to initiate the attack…

  • CVE-2025-53107HigJul 1, 2025
    risk 0.44cvss 7.5epss 0.27

    @cyanheads/git-mcp-server is an MCP server designed to interact with Git repositories. Prior to version 2.1.5, there is a command injection vulnerability caused by the unsanitized use of input parameters within a call to child_process.exec, enabling an attacker to inject…

  • CVE-2025-23170MedJun 19, 2025
    risk 0.44cvss 6.7epss 0.01

    The Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the Director shell via Shell-In-A-Box. The underlying Python script, shell-connect.py, is vulnerable to command injection through the user argument. This allows an…

  • CVE-2025-5447MedJun 2, 2025
    risk 0.44cvss 6.3epss 0.33

    A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. It has been declared as critical. This vulnerability affects the function ssid1MACFilter of the file /goform/ssid1MACFilter. The…

  • CVE-2024-48015MedMar 17, 2025
    risk 0.44cvss 6.7epss 0.01

    Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this…

  • CVE-2025-0396HigJan 12, 2025
    risk 0.44cvss 7.8epss 0.01

    A vulnerability, which was classified as critical, has been found in exelban stats up to 2.11.21. This issue affects the function shouldAcceptNewConnection of the component XPC Service. The manipulation leads to command injection. It is possible to launch the attack on the local…

  • CVE-2024-53899HigNov 24, 2024
    risk 0.44cvss 7.8epss 0.02

    virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.