VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,816)

page 181 of 191
  • CVE-2025-59376LowSep 15, 2025
    risk 0.24cvss 3.7epss 0.00

    feiskyer mcp-kubernetes-server through 0.1.11 does not consider chained commands in the implementation of --disable-write and --disable-delete, e.g., it allows a "kubectl version; kubectl delete pod" command because the first word (i.e., "version") is not a write or delete…

  • CVE-2024-9773LowMar 27, 2025
    risk 0.24cvss 3.7epss 0.00

    An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all versions starting from 17.9 before 17.8.3, all versions starting from 17.10 before 17.10.1. An input validation issue in the Harbor registry integration could have allowed a…

  • CVE-2024-8402LowMar 13, 2025
    risk 0.24cvss 3.7epss 0.00

    An issue was discovered in GitLab EE affecting all versions starting from 17.2 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. An input validation issue in the Google Cloud IAM integration feature could have enabled a…

  • CVE-2022-43695MedNov 14, 2022
    risk 0.24cvss 4.8epss 0.01

    Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Stored Cross-Site Scripting (XSS) in dashboard/system/express/entities/associations because Concrete CMS allows association with an entity name that doesn’t exist or, if it does exist,…

  • CVE-2021-38372LowAug 10, 2021
    risk 0.24cvss 3.7epss 0.01

    In KDE Trojita 0.7, man-in-the-middle attackers can create new folders because untagged responses from an IMAP server are accepted before STARTTLS.

  • CVE-2025-6945LowNov 15, 2025
    risk 0.23cvss 3.5epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 17.8 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to leak sensitive information from confidential issues by injecting hidden prompts into merge…

  • CVE-2024-54681LowJan 17, 2025
    risk 0.23cvss 3.5epss 0.00

    Multiple bash files were present in the application's private directory. Bash files can be used on their own, by an attacker that has already full access to the mobile platform to compromise the translations for the application.

  • CVE-2024-0325LowFeb 1, 2024
    risk 0.23cvss 3.6epss 0.01

    In Helix Sync versions prior to 2024.1, a local command injection was identified. Reported by Bryan Riggins.  

  • CVE-2023-26430LowAug 2, 2023
    risk 0.23cvss 3.5epss 0.01

    Attackers with access to user accounts can inject arbitrary control characters to SIEVE mail-filter rules. This could be abused to access SIEVE extension that are not allowed by App Suite or to inject rules which would break per-user filter processing, requiring manual cleanup…

  • CVE-2023-26429LowJun 20, 2023
    risk 0.23cvss 3.5epss 0.01

    Control characters were not removed when exporting user feedback content. This allowed attackers to include unexpected content via user feedback and potentially break the exported data structure. We now drop all control characters that are not whitespace character during the…

  • CVE-2020-15228LowOct 1, 2020
    risk 0.23cvss 3.5epss 0.01

    In the `@actions/core` npm module before version 1.2.6,`addPath` and `exportVariable` functions communicate with the Actions Runner over stdout by generating a string in a specific format. Workflows that log untrusted data to stdout may invoke these commands, resulting in the…

  • CVE-2025-48979LowAug 29, 2025
    risk 0.22cvss 3.4epss 0.00

    An Improper Input Validation in UISP Application could allow a Command Injection by a malicious actor with High Privileges and local access.

  • CVE-2026-20671LowFeb 11, 2026
    risk 0.20cvss 3.1epss 0.00

    A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker in a privileged network position may…

  • CVE-2024-22122LowAug 12, 2024
    risk 0.20cvss 3.0epss 0.02

    Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on Zabbix server side. Attacker can run test of SMS providing specially crafted phone number and execute additional AT…

  • CVE-2026-25046LowJan 29, 2026
    risk 0.19cvss 2.9epss 0.00

    Kimi Agent SDK is a set of libraries that expose the Kimi Code (Kimi CLI) agent runtime in applications. The vsix-publish.js and ovsx-publish.js scripts pass filenames to execSync() as shell command strings. Prior to version 0.1.6, filenames containing shell metacharacters like…

  • CVE-2020-5299MedJun 3, 2020
    risk 0.19cvss 4.0epss 0.01

    In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, any users with the ability to modify any data that could eventually be exported as a CSV file from the `ImportExportController` could potentially introduce a CSV injection into the data to…

  • CVE-2025-41721LowOct 22, 2025
    risk 0.18cvss 2.7epss 0.00

    A high privileged remote attacker can influence the parameters passed to the openssl command due to improper neutralization of special elements when adding a password protected self-signed certificate.

  • CVE-2019-4635LowJan 28, 2020
    risk 0.18cvss 2.7epss 0.01

    IBM Security Secret Server 10.7 could allow a privileged user to perform unauthorized command injection due to imporoper input neutralization of special elements. IBM X-Force ID: 170011.

  • CVE-2025-52687LowJul 16, 2025
    risk 0.16cvss 2.4epss 0.00

    Successful exploitation of the vulnerability could allow an attacker with administrator credentials for the access point to inject malicious JavaScript into the payload of web traffics, potentially leading to session hijacking and denial-of-service (DoS).

  • CVE-2024-34713LowMay 14, 2024
    risk 0.16cvss 3.5epss 0.00

    sshproxy is used on a gateway to transparently proxy a user SSH connection on the gateway to an internal host via SSH. Prior to version 1.6.3, any user authorized to connect to a ssh server using `sshproxy` can inject options to the `ssh` command executed by `sshproxy`. All…