VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,816)

page 184 of 191
  • CVE-2026-7849CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.00

    Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root.

  • CVE-2026-16763MedJul 23, 2026
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected element is an unknown function of the file src/index.js of the component Configuration Handler. The manipulation of the argument custom.localstack.docker.compose_file leads to os command…

  • CVE-2026-16735MedJul 23, 2026
    risk 0.00cvss 5.3epss 0.01

    A security vulnerability has been detected in release-it conventional-changelog up to 11.0.1. This affects the function writeChangelog of the file index.js of the component Changelog File Handler. Such manipulation of the argument infile leads to os command injection. The attack…

  • CVE-2026-16630MedJul 22, 2026
    risk 0.00cvss 5.3epss 0.01

    A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the function child_process.exec of the file package.json. The manipulation leads to os command injection. An attack has to be approached locally. The exploit has been…

  • CVE-2026-16629MedJul 22, 2026
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was identified in danger danger-js up to 13.0.7. Impacted is the function danger.git.diffForFile of the file source/platforms/git/localGetFileAtSHA.ts of the component CLI. Such manipulation of the argument File leads to os command injection. The attack needs to…

  • CVE-2026-16628MedJul 22, 2026
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was detected in oclif up to 4.23.16. Affected by this vulnerability is the function child_process.exec of the component JIT Plugin Entry Handler. Performing a manipulation of the argument jitPlugins results in os command injection. The attack is only possible…

  • CVE-2026-16492MedJul 22, 2026
    risk 0.00cvss 5.5epss 0.02

    A weakness has been identified in umijs umi up to 4.6.63. The affected element is the function git.getFileCreateInfo of the file packages/utils/src/getFileGitIno.ts of the component GIT File Helper. This manipulation causes os command injection. The exploit has been made…

  • CVE-2026-16489MedJul 22, 2026
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was identified in jsforce up to 3.10.16. This issue affects the function _execCommand in the library lib/registry/sfdx.js of the component SFDX Connection Registry. The manipulation leads to os command injection. The attack can only be performed from a local…

  • CVE-2026-16488MedJul 22, 2026
    risk 0.00cvss 5.0epss 0.01

    A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. This vulnerability affects the function subprocess.Popen of the file minicode/config.py of the component Project File Handler. Executing a manipulation can lead to os command injection. The attack may be launched…

  • CVE-2026-47690HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.00

    MeltanoHub is the source code for hub.meltano.com, the central place for Meltano plugins. Versions of the repo prior to commit 923820de8f64d753951fbbd54f7282a3d5f75173 were vulnerable to exfiltration of `GITHUB_TOKEN` with write permissions to the repository. The vulnerable…

  • CVE-2026-44879HigJul 21, 2026
    risk 0.00cvss 7.2epss 0.02

    A vulnerability in the command line interface of ECOS devices could allow a highly privileged, authenticated remote attacker to perform command injection on certain CLI commands. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying…

  • CVE-2026-16448MedJul 21, 2026
    risk 0.00cvss 6.3epss 0.01

    A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The affected element is…

  • CVE-2026-16133MedJul 18, 2026
    risk 0.00cvss 5.0epss 0.01

    A flaw has been found in LiuMengxuan04 MiniCode 0.1.0. Affected by this vulnerability is the function child_process.spawn of the file mcp.ts. Executing a manipulation can lead to command injection. The attack can be launched remotely. The attack requires a high level of…

  • CVE-2026-52199CriJul 17, 2026
    risk 0.00cvss 9.1epss 0.01

    An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component

  • CVE-2025-65720CriJul 15, 2026
    risk 0.00cvss 9.8epss 0.01

    An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted HTML page.

  • CVE-2026-46709HigJul 15, 2026
    risk 0.00cvss 7.8epss 0.00

    Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.234, Tabby inserts dropped file paths from tabby-electron/src/pathDrop.ts into the active shell without neutralizing command substitution metacharacters such as $(…) and `…`, so the incomplete…

  • CVE-2026-56197HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network.

  • CVE-2026-55145MedJul 14, 2026
    risk 0.00cvss 6.3epss 0.00

    Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampering over a network.

  • CVE-2026-50488HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper neutralization of special elements used in a command ('command injection') in Windows Clipboard User Service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-58635HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.