VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,816)

page 170 of 191
  • CVE-2024-28328MedApr 26, 2024
    risk 0.35cvss 5.4epss 0.00

    CSV Injection vulnerability in the Asus RT-N12+ router allows administrator users to inject arbitrary commands or formulas in the client name parameter which can be triggered and executed in a different user session upon exporting to CSV format.

  • CVE-2023-28012MedJul 27, 2023
    risk 0.35cvss 5.4epss 0.01

    HCL BigFix Mobile is vulnerable to a command injection attack. An authenticated attacker could run arbitrary shell commands on the WebUI server.

  • CVE-2022-29256MedMay 25, 2022
    risk 0.35cvss 6.5epss 0.00

    sharp is an application for Node.js image processing. Prior to version 0.30.5, there is a possible vulnerability in logic that is run only at `npm install` time when installing versions of `sharp` prior to the latest v0.30.5. If an attacker has the ability to set the value of…

  • CVE-2017-18442MedAug 2, 2019
    risk 0.35cvss 5.3epss 0.01

    cPanel before 64.0.21 allows demo accounts to execute Cpanel::SPFUI API commands (SEC-246).

  • CVE-2017-2324MedApr 24, 2017
    risk 0.35cvss 5.3epss 0.02

    A command injection vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a network-based malicious attacker to cause a denial of service condition.

  • CVE-2026-19334MedAug 9, 2026
    risk 0.34cvss 5.3epss 0.01

    A flaw has been found in NightTrek Ollama-mcp up to 80cf2e17cfc144963a475b619093a2d13c13dbc9. This affects an unknown part of the file src/index.ts. This manipulation of the argument name/modelfile/source/destination causes command injection. The attack can only be executed…

  • CVE-2026-19333MedAug 9, 2026
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was detected in NightTrek Supabase-MCP cc994ab2d2a36b0af6ee7c7f3e6ce8e08cda2170/db03237d92f7dc2f0da0d70a87dba84ebcde5b66. Affected by this issue is some unknown functionality of the component generate_types. The manipulation of the argument schema results in…

  • CVE-2026-19332MedAug 9, 2026
    risk 0.34cvss 5.3epss 0.01

    A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0. Affected by this vulnerability is an unknown functionality of the component run_openlane/view_waveform. The manipulation of the argument design_name/vcd_file leads to command injection. Local access is required…

  • CVE-2026-19329MedAug 9, 2026
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in andreahaku codex_mcp up to 1ff521cc6cc57cfe56ddef946c644b8534771390. The affected element is an unknown function of the file src/codex-process-simple.ts of the component ask MCP Tool. The manipulation of the argument model results in command…

  • CVE-2026-19284MedAug 8, 2026
    risk 0.34cvss 5.3epss 0.01

    A security vulnerability has been detected in MauricioMilano coder-api up to 1.1.0. Affected is the function createProject of the file src/core/projects.ts of the component Projects Endpoint. The manipulation leads to command injection. The attack must be carried out locally.…

  • CVE-2026-19282MedAug 8, 2026
    risk 0.34cvss 5.3epss 0.01

    A weakness has been identified in andreahaku llm_memory_mcp up to f11dc8bcff3ff8cf943a2945f99ff3b0bdc8a6d0. This impacts the function auto.capture of the file src/autolearn/GitHooksManager.ts of the component llm_memory_mcp. Executing a manipulation of the argument hash can lead…

  • CVE-2026-19281MedAug 8, 2026
    risk 0.34cvss 5.3epss 0.01

    A security flaw has been discovered in adolfosalasgomez3011 slidev-builder-mcp 2.1.0. This affects the function generateChart of the file src/tools/generateAssets.ts of the component generateAssets Tool. Performing a manipulation of the argument outputDir results in command…

  • CVE-2026-19243MedAug 7, 2026
    risk 0.34cvss 6.3epss 0.02

    A security vulnerability has been detected in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component Shell Allowlist Handler. Such manipulation leads to os command injection. The…

  • CVE-2026-19045MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.01

    A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the function SecretDialog.showSecretDialog of the file src/utils/secretDialog.ts of the component get_credential_from_user. This manipulation of the argument Description causes command…

  • CVE-2026-19041MedAug 6, 2026
    risk 0.34cvss 6.3epss 0.02

    A vulnerability has been found in MissionSquad mcp-api up to 1.11.8. The impacted element is the function this.packageService.installPackage of the file src/controllers/packages.ts of the component NPM Package Version Handler. The manipulation leads to command injection. It is…

  • CVE-2026-18980MedAug 6, 2026
    risk 0.34cvss 6.3epss 0.01

    A vulnerability was identified in nearai ironclaw up to 0.29.1. Affected is the function classify_command_risk of the file src/tools/builtin/shell.rs. Such manipulation leads to command injection. The attack may be launched remotely. The exploit is publicly available and might…

  • CVE-2026-16733MedJul 23, 2026
    risk 0.34cvss 5.3epss 0.01

    A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell.exec of the file src/index.js of the component Branch Handler. This manipulation of the argument --branch causes os command injection. The attack is restricted…

  • CVE-2026-11408MedJun 6, 2026
    risk 0.34cvss 6.3epss 0.01

    A vulnerability was identified in vertex-app vertex up to 2026.02.12. This issue affects some unknown processing of the file app/model/LogMod.js of the component Log Viewer Endpoint. Such manipulation of the argument req.query leads to os command injection. The attack can be…

  • CVE-2026-10550MedJun 2, 2026
    risk 0.34cvss 6.3epss 0.01

    A weakness has been identified in elunez eladmin up to 2.7. This vulnerability affects unknown code of the file App.java of the component Application Deployment Module. This manipulation of the argument uploadPath causes command injection. Remote exploitation of the attack is…

  • CVE-2026-8112MedMay 7, 2026
    risk 0.34cvss 6.3epss 0.03

    A vulnerability was found in 8421bit MiniClaw up to 223c16a1088e138838dcbd18cd65a37c35ac5a84. Affected is the function executeCognitivePulse of the file src/kernel.ts. Performing a manipulation results in os command injection. It is possible to initiate the attack remotely. The…