VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,816)

page 165 of 191
  • CVE-2021-21595MedAug 16, 2021
    risk 0.39cvss 6.0epss 0.00

    Dell EMC PowerScale OneFS versions 8.2.x - 9.1.1.x contain an improper neutralization of special elements used in an OS command. This vulnerability could allow the compadmin user to elevate privileges. This only impacts Smartlock WORM compliance mode clusters as a critical…

  • CVE-2021-31799HigJul 30, 2021
    risk 0.39cvss 7.0epss 0.01

    In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.

  • CVE-2021-1382MedMar 24, 2021
    risk 0.39cvss 6.0epss 0.01

    A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root privileges on the underlying operating system. This vulnerability is due to insufficient input validation on certain CLI…

  • CVE-2013-3364higAug 31, 2020
    risk 0.39cvss epss 0.05

    ep_imageconvert is a plugin for [Etherpad Lite](https://github.com/ether/etherpad-lite). ep_imageconvert <= 0.0.2 is vulnerable to remote command injection. Authentication is not required for remote exploitation. ## Recommendation Update to version 0.0.3 or greater.

  • CVE-2026-41153MedApr 17, 2026
    risk 0.38cvss 5.8epss 0.00

    In JetBrains Junie before 252.549.29 command execution was possible via malicious project file

  • CVE-2025-31710MedJun 3, 2025
    risk 0.38cvss 5.9epss 0.00

    In engineermode service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed.

  • CVE-2024-56087MedDec 16, 2024
    risk 0.38cvss 5.9epss 0.00

    An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while querying Search Template Dashboard. These are executed, leading to Server-Side Template Injection.

  • CVE-2024-56085MedDec 16, 2024
    risk 0.38cvss 5.9epss 0.00

    An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template Dashboard. These are executed, leading to Server-Side Template Injection.

  • CVE-2024-35401MedMay 28, 2024
    risk 0.38cvss 5.9epss 0.01

    TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.

  • CVE-2020-29547MedMay 29, 2023
    risk 0.38cvss 5.9epss 0.01

    An issue was discovered in Citadel through webcit-926. Meddler-in-the-middle attackers can pipeline commands after POP3 STLS, IMAP STARTTLS, or SMTP STARTTLS commands, injecting cleartext commands into an encrypted user session. This can lead to credential disclosure.

  • CVE-2020-15955MedAug 17, 2021
    risk 0.38cvss 5.9epss 0.01

    In s/qmail through 4.0.07, an active MitM can inject arbitrary plaintext commands into a STARTTLS encrypted session between an SMTP client and s/qmail. This allows e-mail messages and user credentials to be sent to the MitM attacker.

  • CVE-2021-38370MedAug 10, 2021
    risk 0.38cvss 5.9epss 0.02

    In Alpine before 2.25, untagged responses from an IMAP server are accepted before STARTTLS.

  • CVE-2021-21406MedJul 21, 2021
    risk 0.38cvss 5.8epss 0.01

    Combodo iTop is an open source, web based IT Service Management tool. In versions prior to 2.7.4, there is a command injection vulnerability in the Setup Wizard when providing Graphviz executable path. The vulnerability is patched in version 2.7.4 and 3.0.0.

  • CVE-2018-20523MedJun 7, 2019
    risk 0.38cvss 5.3epss 0.10

    Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a third-party application can read the user's cleartext browser history via an app.provider.query…

  • CVE-2017-16087higMay 29, 2019
    risk 0.38cvss epss

    ## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-wp3j-gv53-4pg8. This link is maintained to preserve external references. ## Original Description Affected versions of `fs-git` do not sanitize strings passed into the `buildCommand` method,…

  • CVE-2026-23653MedApr 14, 2026
    risk 0.37cvss 5.7epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an authorized attacker to disclose information over a network.

  • CVE-2025-14276MedDec 8, 2025
    risk 0.37cvss 5.6epss 0.02

    A vulnerability was determined in Ilevia EVE X1 Server up to 4.6.5.0.eden. Impacted is an unknown function of the file /ajax/php/leaf_search.php. This manipulation of the argument line causes command injection. The attack can be initiated remotely. A high degree of complexity is…

  • CVE-2025-27233MedSep 12, 2025
    risk 0.37cvss epss 0.00

    Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. This can be used to leak the NTLMv2 hash from a Windows system.

  • CVE-2025-22237MedJun 13, 2025
    risk 0.37cvss 6.7epss 0.00

    An attacker with access to a minion key can exploit the 'on demand' pillar functionality with a specially crafted git url which could cause and arbitrary command to be run on the master with the same privileges as the master process.

  • CVE-2025-5525MedJun 3, 2025
    risk 0.37cvss 5.6epss 0.03

    A vulnerability was found in Jrohy trojan up to 2.15.3. It has been declared as critical. This vulnerability affects the function LogChan of the file trojan/util/linux.go. The manipulation of the argument c leads to os command injection. The attack can be initiated remotely. The…