VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,970)

page 177 of 199
  • CVE-2024-38896MedJun 24, 2024
    risk 0.35cvss 5.3epss 0.01

    WAVLINK WN551K1 found a command injection vulnerability through the start_hour parameter of /cgi-bin/nightled.cgi.

  • CVE-2024-38894MedJun 24, 2024
    risk 0.35cvss 5.3epss 0.01

    WAVLINK WN551K1 found a command injection vulnerability through the IP parameter of /cgi-bin/touchlist_sync.cgi.

  • CVE-2024-34352MedMay 14, 2024
    risk 0.35cvss 6.5epss 0.01

    1Panel is an open source Linux server operation and maintenance management panel. Prior to v1.10.3-lts, there are many command injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. The mirror…

  • CVE-2024-33113MedMay 6, 2024
    risk 0.35cvss 5.3epss 0.03

    D-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php.

  • CVE-2024-32884MedApr 26, 2024
    risk 0.35cvss 6.4epss 0.01

    gitoxide is a pure Rust implementation of Git. `gix-transport` does not check the username part of a URL for text that the external `ssh` program would interpret as an option. A specially crafted clone URL can smuggle options to SSH. The possibilities are syntactically limited,…

  • CVE-2024-28328MedApr 26, 2024
    risk 0.35cvss 5.4epss 0.00

    CSV Injection vulnerability in the Asus RT-N12+ router allows administrator users to inject arbitrary commands or formulas in the client name parameter which can be triggered and executed in a different user session upon exporting to CSV format.

  • CVE-2023-28012MedJul 27, 2023
    risk 0.35cvss 5.4epss 0.01

    HCL BigFix Mobile is vulnerable to a command injection attack. An authenticated attacker could run arbitrary shell commands on the WebUI server.

  • CVE-2022-29256MedMay 25, 2022
    risk 0.35cvss 6.5epss 0.00

    sharp is an application for Node.js image processing. Prior to version 0.30.5, there is a possible vulnerability in logic that is run only at `npm install` time when installing versions of `sharp` prior to the latest v0.30.5. If an attacker has the ability to set the value of…

  • CVE-2017-18442MedAug 2, 2019
    risk 0.35cvss 5.3epss 0.01

    cPanel before 64.0.21 allows demo accounts to execute Cpanel::SPFUI API commands (SEC-246).

  • CVE-2017-2324MedApr 24, 2017
    risk 0.35cvss 5.3epss 0.02

    A command injection vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a network-based malicious attacker to cause a denial of service condition.

  • CVE-2026-93533MedSep 18, 2026
    risk 0.34cvss 6.3epss 0.01

    A vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the function DoctorCommand::checkSshConnectivity/DoctorCommand::checkRemoteTools of the file app/Commands/DoctorCommand.php of the component Doctor Command Handler. This manipulation of the argument host…

  • CVE-2026-92993MedSep 17, 2026
    risk 0.34cvss 6.3epss 0.01

    A vulnerability was detected in Dromara mayfly-go up to 1.11.5. The impacted element is the function RunMachineScript of the file server/internal/machine/api/machine_script.go of the component Machine Script Feature. The manipulation of the argument params results in os command…

  • CVE-2026-81380MedSep 8, 2026
    risk 0.34cvss 5.3epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-19334MedAug 9, 2026
    risk 0.34cvss 5.3epss 0.01

    A flaw has been found in NightTrek Ollama-mcp up to 80cf2e17cfc144963a475b619093a2d13c13dbc9. This affects an unknown part of the file src/index.ts. This manipulation of the argument name/modelfile/source/destination causes command injection. The attack can only be executed…

  • CVE-2026-19333MedAug 9, 2026
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was detected in NightTrek Supabase-MCP cc994ab2d2a36b0af6ee7c7f3e6ce8e08cda2170/db03237d92f7dc2f0da0d70a87dba84ebcde5b66. Affected by this issue is some unknown functionality of the component generate_types. The manipulation of the argument schema results in…

  • CVE-2026-19332MedAug 9, 2026
    risk 0.34cvss 5.3epss 0.01

    A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0. Affected by this vulnerability is an unknown functionality of the component run_openlane/view_waveform. The manipulation of the argument design_name/vcd_file leads to command injection. Local access is required…

  • CVE-2026-19329MedAug 9, 2026
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in andreahaku codex_mcp up to 1ff521cc6cc57cfe56ddef946c644b8534771390. The affected element is an unknown function of the file src/codex-process-simple.ts of the component ask MCP Tool. The manipulation of the argument model results in command…

  • CVE-2026-19284MedAug 8, 2026
    risk 0.34cvss 5.3epss 0.01

    A security vulnerability has been detected in MauricioMilano coder-api up to 1.1.0. Affected is the function createProject of the file src/core/projects.ts of the component Projects Endpoint. The manipulation leads to command injection. The attack must be carried out locally.…

  • CVE-2026-19282MedAug 8, 2026
    risk 0.34cvss 5.3epss 0.01

    A weakness has been identified in andreahaku llm_memory_mcp up to f11dc8bcff3ff8cf943a2945f99ff3b0bdc8a6d0. This impacts the function auto.capture of the file src/autolearn/GitHooksManager.ts of the component llm_memory_mcp. Executing a manipulation of the argument hash can lead…

  • CVE-2026-19281MedAug 8, 2026
    risk 0.34cvss 5.3epss 0.01

    A security flaw has been discovered in adolfosalasgomez3011 slidev-builder-mcp 2.1.0. This affects the function generateChart of the file src/tools/generateAssets.ts of the component generateAssets Tool. Performing a manipulation of the argument outputDir results in command…