VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,816)

page 187 of 191
  • CVE-2025-53098HigJun 27, 2025
    risk 0.00cvss 8.1epss 0.01

    Roo Code is an AI-powered autonomous coding agent. The project-specific MCP configuration for the Roo Code agent is stored in the `.roo/mcp.json` file within the VS Code workspace. Because the MCP configuration format allows for execution of arbitrary commands, prior to version…

  • CVE-2025-52483CriJun 25, 2025
    risk 0.00cvss 9.8epss 0.00

    Registrator is a GitHub app that automates creation of registration pull requests for julia packages to the General registry. Prior to version 1.9.5, if the clone URL returned by GitHub is malicious (or can be injected using upstream vulnerabilities) a shell script injection can…

  • CVE-2025-49823NonJun 17, 2025
    risk 0.00cvss 0.0epss 0.00

    (conda) Constructor is a tool which allows constructing an installer for a collection of conda packages. Prior to version 3.11.3, shell installer scripts process the installation prefix (user_prefix) using an eval statement, which executes unsanitized user input as shell code.…

  • CVE-2025-46735LowMay 6, 2025
    risk 0.00cvss epss 0.01

    Terraform WinDNS Provider allows users to manage their Windows DNS server resources through Terraform. A security issue has been found in Terraform WinDNS Provider before version `1.0.5`. The `windns_record` resource did not sanitize the input variables. This could lead to…

  • CVE-2024-8156CriMar 20, 2025
    risk 0.00cvss 9.8epss 0.02

    A command injection vulnerability exists in the workflow-checker.yml workflow of significant-gravitas/autogpt. The untrusted user input `github.head.ref` is used insecurely, allowing an attacker to inject arbitrary commands. This vulnerability affects versions up to and…

  • CVE-2022-1884CriNov 15, 2024
    risk 0.00cvss 9.8epss 0.02

    A remote command execution vulnerability exists in gogs/gogs versions <=0.12.7 when deployed on a Windows server. The vulnerability arises due to improper validation of the `tree_path` parameter during file uploads. An attacker can set `tree_path=.git.` to upload a file into the…

  • CVE-2024-51736NonNov 6, 2024
    risk 0.00cvss 0.0epss 0.00

    Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. On Windows, when an executable file named `cmd.exe` is located in the current working directory it will be called by the `Process` class when preparing command arguments,…

  • CVE-2024-9287HigOct 22, 2024
    risk 0.00cvss 7.8epss 0.01

    A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This…

  • CVE-2024-46256CriSep 27, 2024
    risk 0.00cvss 9.8epss 0.03

    A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certificate.

  • CVE-2024-25639MedJul 8, 2024
    risk 0.00cvss 5.9epss 0.01

    Khoj is an application that creates personal AI agents. The Khoj Obsidian, Desktop and Web clients inadequately sanitize the AI model's response and user inputs. This can trigger Cross Site Scripting (XSS) via Prompt Injection from untrusted documents either indexed by the user…

  • CVE-2024-37385CriJun 7, 2024
    risk 0.00cvss 9.8epss 0.01

    Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete fix for CVE-2020-12641.

  • CVE-2024-32027CriApr 16, 2024
    risk 0.00cvss 9.1epss 0.03

    Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss v22.6.1 is vulnerable to command injection in `finetune_gui.py` This vulnerability is fixed in 23.1.5.

  • CVE-2024-32026CriApr 16, 2024
    risk 0.00cvss 9.1epss 0.03

    Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a command injection in `git_caption_gui.py`. This vulnerability is fixed in 23.1.5.

  • CVE-2024-32025CriApr 16, 2024
    risk 0.00cvss 9.1epss 0.02

    Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a command injection in `group_images_gui.py`. This vulnerability is fixed in 23.1.5.

  • CVE-2024-32022CriApr 16, 2024
    risk 0.00cvss 9.1epss 0.03

    Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to command injection in basic_caption_gui.py. This vulnerability is fixed in 23.1.5.

  • CVE-2024-29864CriMar 21, 2024
    risk 0.00cvss 9.8epss 0.03

    Distrobox before 1.7.0.1 allows attackers to execute arbitrary code via command injection into exported executables.

  • CVE-2024-25082MedFeb 26, 2024
    risk 0.00cvss 6.5epss 0.02

    Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.

  • CVE-2024-25081MedFeb 26, 2024
    risk 0.00cvss 4.2epss 0.01

    Splinefont in FontForge through 20230101 allows command injection via crafted filenames.

  • CVE-2024-21663CriJan 9, 2024
    risk 0.00cvss 9.9epss 0.02

    Discord-Recon is a Discord bot created to automate bug bounty recon, automated scans and information gathering via a discord server. Discord-Recon is vulnerable to remote code execution. An attacker is able to execute shell commands in the server without having an admin role.…

  • CVE-2023-6848HigDec 16, 2023
    risk 0.00cvss 7.3epss 0.02

    A vulnerability was found in kalcaddle kodbox up to 1.48. It has been declared as critical. Affected by this vulnerability is the function check of the file plugins/officeViewer/controller/libreOffice/index.class.php. The manipulation of the argument soffice leads to command…