VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,816)

page 171 of 191
  • CVE-2026-7629MedMay 2, 2026
    risk 0.34cvss 6.3epss 0.01

    A flaw has been found in kleneway awesome-cursor-mpc-server up to 2.0.1. Impacted is the function runCodeReviewTool of the file src/tools/codeReview.ts of the component Ccode-Review Tool. Executing a manipulation can lead to command injection. The attack may be launched…

  • CVE-2026-7628MedMay 2, 2026
    risk 0.34cvss 6.3epss 0.01

    A vulnerability was detected in crazyrabbitLTC mcp-code-review-server up to 0.1.0. This issue affects the function executeRepomix of the file src/repomix.ts of the component RepoMix Command Handler. Performing a manipulation results in command injection. The attack may be…

  • CVE-2026-6141MedApr 13, 2026
    risk 0.34cvss 6.3epss 0.01

    A vulnerability was determined in danielmiessler Personal_AI_Infrastructure up to 2.3.0. Affected is an unknown function of the file Skills/Parser/Tools/parse_url.ts. Executing a manipulation can lead to os command injection. The attack may be launched remotely. The exploit has…

  • CVE-2026-6118MedApr 12, 2026
    risk 0.34cvss 6.3epss 0.02

    A vulnerability was determined in AstrBotDevs AstrBot up to 4.22.1. Impacted is the function add_mcp_server of the file astrbot/dashboard/routes/tools.py of the component MCP Endpoint. This manipulation of the argument command causes command injection. The attack is possible to…

  • CVE-2026-5831MedApr 9, 2026
    risk 0.34cvss 6.3epss 0.01

    A security flaw has been discovered in Agions taskflow-ai up to 2.1.8. This impacts an unknown function of the file src/mcp/server/handlers.ts of the component terminal_execute. Performing a manipulation results in os command injection. The attack is possible to be carried out…

  • CVE-2026-3484MedMar 3, 2026
    risk 0.34cvss 6.3epss 0.03

    A vulnerability was detected in PhialsBasement nmap-mcp-server up to bee6d23547d57ae02460022f7c78ac0893092e38. Affected by this issue is the function child_process.exec of the file src/index.ts of the component Nmap CLI Command Handler. The manipulation results in command…

  • CVE-2026-3102MedFeb 24, 2026
    risk 0.34cvss 6.3epss 0.04

    A vulnerability was determined in exiftool up to 13.49 on macOS. This issue affects the function SetMacOSTags of the file lib/Image/ExifTool/MacOS.pm of the component PNG File Parser. This manipulation of the argument DateTimeOriginal causes os command injection. The attack is…

  • CVE-2026-2178MedFeb 8, 2026
    risk 0.34cvss 6.3epss 0.03

    A vulnerability was found in r-huijts xcode-mcp-server up to f3419f00117aa9949e326f78cc940166c88f18cb. This affects the function registerXcodeTools of the file src/tools/xcode/index.ts of the component run_lldb. The manipulation of the argument args results in command injection.…

  • CVE-2026-2130MedFeb 8, 2026
    risk 0.34cvss 6.3epss 0.02

    A vulnerability was determined in BurtTheCoder mcp-maigret up to 1.0.12. This affects an unknown part of the file src/index.ts of the component search_username. Executing a manipulation of the argument Username can lead to command injection. The attack may be launched remotely.…

  • CVE-2025-46365MedNov 5, 2025
    risk 0.34cvss 5.3epss 0.00

    Dell CloudLink, versions prior 8.1.1, contain a Command Injection vulnerability which can be exploited by an Authenticated attacker to cause Command Injection on an affected Dell CloudLink.

  • CVE-2025-10619MedSep 17, 2025
    risk 0.34cvss 6.3epss 0.02

    A vulnerability was detected in sequa-ai sequa-mcp up to 1.0.13. This affects the function redirectToAuthorization of the file src/helpers/node-oauth-client-provider.ts of the component OAuth Server Discovery. Performing manipulation results in os command injection. Remote…

  • CVE-2025-55372MedSep 2, 2025
    risk 0.34cvss 5.3epss 0.00

    An arbitrary file upload vulnerability in Beakon Application before v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2025-9654MedAug 29, 2025
    risk 0.34cvss 6.3epss 0.01

    A security flaw has been discovered in AiondaDotCom mcp-ssh up to 1.0.3. Affected by this issue is some unknown functionality of the file server-simple.mjs. Performing manipulation results in command injection. The attack can be initiated remotely. Upgrading to version 1.0.4 and…

  • CVE-2025-45011MedApr 30, 2025
    risk 0.34cvss 5.3epss 0.00

    A HTML Injection vulnerability was discovered in the foreigner-search.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the searchdata POST request parameter.

  • CVE-2025-45010MedApr 30, 2025
    risk 0.34cvss 5.3epss 0.00

    A HTML Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the fromdate and todate POST request parameters.

  • CVE-2025-45009MedApr 30, 2025
    risk 0.34cvss 5.3epss 0.00

    A HTML Injection vulnerability was discovered in the normal-search.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the searchdata parameter.

  • CVE-2024-27763MedMar 12, 2025
    risk 0.34cvss 5.3epss 0.00

    XPixelGroup BasicSR through 1.4.2 might locally allow code execution in contrived situations where "scontrol show hostname" is executed in the presence of a crafted SLURM_NODELIST environment variable.

  • CVE-2024-57685MedFeb 24, 2025
    risk 0.34cvss 5.3epss 0.00

    An issue in sparkshop v.1.1.7 and before allows a remote attacker to execute arbitrary code via a crafted phar file.

  • CVE-2023-1000MedApr 27, 2024
    risk 0.34cvss 6.3epss 0.01

    A vulnerability was found in cyanomiko dcnnt-py up to 0.9.0. It has been classified as critical. Affected is the function main of the file dcnnt/plugins/notifications.py of the component Notification Handler. The manipulation leads to command injection. It is possible to launch…

  • CVE-2024-21117MedApr 16, 2024
    risk 0.34cvss 5.3epss 0.00

    Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). Supported versions that are affected are 8.5.6 and 8.5.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where…