VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,816)

page 185 of 191
  • CVE-2026-50520HigJul 14, 2026
    risk 0.00cvss 8.4epss 0.00

    Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute code locally.

  • CVE-2026-48561CriJul 14, 2026
    risk 0.00cvss 9.6epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-15669MedJul 14, 2026
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was found in louisho5 picobot up to 0.2.0. This issue affects the function ExecTool.Execute of the file internal/agent/tools/exec.go of the component exec Tool. The manipulation results in os command injection. The attack requires a local approach. The exploit…

  • CVE-2026-22103CriJul 13, 2026
    risk 0.00cvss epss 0.01

    The NPC start endpoint on the web server at port 8090 is vulnerable to command injection.

  • CVE-2026-22095CriJul 13, 2026
    risk 0.00cvss epss 0.01

    The network diagnosis endpoint on the web server at port 8090 is vulnerable to command injection.

  • CVE-2026-15547MedJul 13, 2026
    risk 0.00cvss 6.3epss 0.01

    A weakness has been identified in Shibby Tomato up to 1.28.0000. This affects the function sub_2D048 of the component CIFS Mount Handler. Executing a manipulation of the argument cifs1/cifs2 can lead to os command injection. The attack can be executed remotely. The exploit has…

  • CVE-2026-15546MedJul 13, 2026
    risk 0.00cvss 6.3epss 0.01

    A security flaw has been discovered in Shibby Tomato up to 1.28.0000. Affected by this issue is the function sub_2D568 of the component start_jffs2. Performing a manipulation of the argument jffs2_exec results in os command injection. Remote exploitation of the attack is…

  • CVE-2026-15513MedJul 13, 2026
    risk 0.00cvss 6.3epss 0.01

    A security flaw has been discovered in Wavlink WL-NU516U1 260515. This affects the function wlink_uci_set_value of the file /cgi-bin/adm.cgi. Performing a manipulation of the argument lan_ip results in os command injection. The attack can be initiated remotely. The exploit has…

  • CVE-2026-15511CriJul 12, 2026
    risk 0.00cvss 9.8epss 0.03

    A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. Affected by this vulnerability is the function system_wl_upload_pic_file of the file /usr/bin/webmgnt of the component FastCGI Backend. This manipulation of the argument filename causes os command injection.…

  • CVE-2026-15496MedJul 12, 2026
    risk 0.00cvss 6.3epss 0.01

    A vulnerability was found in SonicCloudOrg sonic-agent up to 2.7.2. The impacted element is the function evalIsFailed of the file sonic-agent/src/main/java/org/cloud/sonic/agent/tests/script/GroovyScriptImpl.java of the component Groovy Script Handler. The manipulation results…

  • CVE-2026-15495MedJul 12, 2026
    risk 0.00cvss 6.3epss 0.02

    A vulnerability has been found in SonicCloudOrg sonic-agent up to 2.7.2. The affected element is an unknown function of the file AndroidWSServer.java of the component Android WebSocket Server. The manipulation of the argument path leads to os command injection. The attack can be…

  • CVE-2026-15487MedJul 12, 2026
    risk 0.00cvss 6.3epss 0.01

    A vulnerability was found in TRENDnet TEW-821DAP 1.11B03. This impacts the function sub_41FBD0 of the file /goform/system_ntp of the component Firmware Update Handler. Performing a manipulation of the argument Hostname results in os command injection. The attack may be initiated…

  • CVE-2026-15486MedJul 12, 2026
    risk 0.00cvss 6.3epss 0.01

    A vulnerability has been found in TRENDnet TEW-821DAP 1.11B03. This affects the function sub_42026C of the file /goform/tools_ddns of the component Firmware Update Handler. Such manipulation of the argument hostname/username/password leads to os command injection. The attack can…

  • CVE-2026-15485MedJul 12, 2026
    risk 0.00cvss 6.3epss 0.01

    A flaw has been found in TRENDnet TEW-821DAP 1.11B03. The impacted element is the function sub_43F2C4 of the file /goform/tools_nslookup of the component DNS Lookup Handler. This manipulation of the argument nslookup_target/dns_server causes os command injection. The attack can…

  • CVE-2026-15481HigJul 12, 2026
    risk 0.00cvss 8.8epss 0.02

    A security flaw has been discovered in Trendnet TEW-635BRM up to 1.00.03. This vulnerability affects the function ipoa_test of the file /sbin/rc of the component IPoA WAN Connection Setup. Performing a manipulation of the argument ipoa_ipaddr results in command injection. The…

  • CVE-2026-59721HigJul 9, 2026
    risk 0.00cvss 7.2epss 0.01

    Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the updateInfraConfigs GraphQL mutation in admin/infra.resolver.ts accepts an attacker-controlled MAILER_SMTP_URL value, and validateSMTPUrl in utils.ts permits path, query, or fragment content that…

  • CVE-2026-15193MedJul 9, 2026
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was determined in AidanPark openclaw-android up to 0.4.0. The affected element is an unknown function of the file android/app/src/main/java/com/openclaw/android/JsBridge.kt of the component Android WebView Bridge. This manipulation causes os command injection.…

  • CVE-2026-15035MedJul 8, 2026
    risk 0.00cvss 5.3epss 0.02

    A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function async_run_command of the file src/openllm/common.py of the component Model Repository Directory Name Handler. Performing a manipulation of the argument cmd results in command injection. Attacking…

  • CVE-2026-15033MedJul 8, 2026
    risk 0.00cvss 6.3epss 0.01

    A flaw has been found in christopherthielen check-peer-dependencies up to 4.3.4. Affected by this vulnerability is the function shelljs.exec of the file dist/packageUtils.js of the component peerDependencies. This manipulation causes os command injection. The attack may be…

  • CVE-2026-14802HigJul 6, 2026
    risk 0.00cvss 7.3epss 0.01

    A vulnerability was detected in react create-react-app up to 5.0.1 on macOS. This affects the function startBrowserProcess of the file openBrowser.js of the component react-dev-utils. Performing a manipulation results in os command injection. Remote exploitation of the attack is…