CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Description
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76
CVEs mapped to this weakness (3,970)
page 192 of 199| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-16492 | Med | 0.00 | 5.5 | 0.04 | Jul 22, 2026 | A weakness has been identified in umijs umi up to 4.6.63. The affected element is the function git.getFileCreateInfo of the file packages/utils/src/getFileGitIno.ts of the component GIT File Helper. This manipulation causes os command injection. The exploit has been made… | ||
| CVE-2026-16489 | Med | 0.00 | 5.3 | 0.01 | Jul 22, 2026 | A vulnerability was identified in jsforce up to 3.10.16. This issue affects the function _execCommand in the library lib/registry/sfdx.js of the component SFDX Connection Registry. The manipulation leads to os command injection. The attack can only be performed from a local… | ||
| CVE-2026-16488 | Med | 0.00 | 5.0 | 0.01 | Jul 22, 2026 | A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. This vulnerability affects the function subprocess.Popen of the file minicode/config.py of the component Project File Handler. Executing a manipulation can lead to os command injection. The attack may be launched… | ||
| CVE-2026-47690 | Hig | 0.00 | 7.5 | 0.01 | Jul 21, 2026 | MeltanoHub is the source code for hub.meltano.com, the central place for Meltano plugins. Versions of the repo prior to commit 923820de8f64d753951fbbd54f7282a3d5f75173 were vulnerable to exfiltration of `GITHUB_TOKEN` with write permissions to the repository. The vulnerable… | ||
| CVE-2026-44879 | Hig | 0.00 | 7.2 | 0.02 | Jul 21, 2026 | A vulnerability in the command line interface of ECOS devices could allow a highly privileged, authenticated remote attacker to perform command injection on certain CLI commands. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying… | ||
| CVE-2026-16448 | Med | 0.00 | 6.3 | 0.01 | Jul 21, 2026 | A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The affected element is… | ||
| CVE-2026-16133 | Med | 0.00 | 5.0 | 0.01 | Jul 18, 2026 | A flaw has been found in LiuMengxuan04 MiniCode 0.1.0. Affected by this vulnerability is the function child_process.spawn of the file mcp.ts. Executing a manipulation can lead to command injection. The attack can be launched remotely. The attack requires a high level of… | ||
| CVE-2026-52199 | Cri | 0.00 | 9.1 | 0.01 | Jul 17, 2026 | An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component | ||
| CVE-2025-65720 | Cri | 0.00 | 9.8 | 0.01 | Jul 15, 2026 | An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted HTML page. | ||
| CVE-2026-46709 | Hig | 0.00 | 7.8 | 0.00 | Jul 15, 2026 | Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.234, Tabby inserts dropped file paths from tabby-electron/src/pathDrop.ts into the active shell without neutralizing command substitution metacharacters such as $(…) and `…`, so the incomplete… | ||
| CVE-2026-56197 | Hig | 0.00 | 8.8 | 0.01 | Jul 14, 2026 | Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network. | ||
| CVE-2026-55145 | Med | 0.00 | 6.3 | 0.01 | Jul 14, 2026 | Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampering over a network. | ||
| CVE-2026-50488 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Improper neutralization of special elements used in a command ('command injection') in Windows Clipboard User Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-58635 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50520 | Hig | 0.00 | 8.4 | 0.00 | Jul 14, 2026 | Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-48561 | Cri | 0.00 | 9.6 | 0.01 | Jul 14, 2026 | Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-15669 | Med | 0.00 | 5.3 | 0.01 | Jul 14, 2026 | A vulnerability was found in louisho5 picobot up to 0.2.0. This issue affects the function ExecTool.Execute of the file internal/agent/tools/exec.go of the component exec Tool. The manipulation results in os command injection. The attack requires a local approach. The exploit… | ||
| CVE-2026-22103 | Cri | 0.00 | — | 0.01 | Jul 13, 2026 | The NPC start endpoint on the web server at port 8090 is vulnerable to command injection. | ||
| CVE-2026-22095 | — | Cri | 0.00 | — | 0.01 | Jul 13, 2026 | The network diagnosis endpoint on the web server at port 8090 is vulnerable to command injection. | |
| CVE-2026-15547 | Med | 0.00 | 6.3 | 0.02 | Jul 13, 2026 | A weakness has been identified in Shibby Tomato up to 1.28.0000. This affects the function sub_2D048 of the component CIFS Mount Handler. Executing a manipulation of the argument cifs1/cifs2 can lead to os command injection. The attack can be executed remotely. The exploit has… |
- risk 0.00cvss 5.5epss 0.04
A weakness has been identified in umijs umi up to 4.6.63. The affected element is the function git.getFileCreateInfo of the file packages/utils/src/getFileGitIno.ts of the component GIT File Helper. This manipulation causes os command injection. The exploit has been made…
- risk 0.00cvss 5.3epss 0.01
A vulnerability was identified in jsforce up to 3.10.16. This issue affects the function _execCommand in the library lib/registry/sfdx.js of the component SFDX Connection Registry. The manipulation leads to os command injection. The attack can only be performed from a local…
- risk 0.00cvss 5.0epss 0.01
A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. This vulnerability affects the function subprocess.Popen of the file minicode/config.py of the component Project File Handler. Executing a manipulation can lead to os command injection. The attack may be launched…
- risk 0.00cvss 7.5epss 0.01
MeltanoHub is the source code for hub.meltano.com, the central place for Meltano plugins. Versions of the repo prior to commit 923820de8f64d753951fbbd54f7282a3d5f75173 were vulnerable to exfiltration of `GITHUB_TOKEN` with write permissions to the repository. The vulnerable…
- risk 0.00cvss 7.2epss 0.02
A vulnerability in the command line interface of ECOS devices could allow a highly privileged, authenticated remote attacker to perform command injection on certain CLI commands. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying…
- risk 0.00cvss 6.3epss 0.01
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The affected element is…
- risk 0.00cvss 5.0epss 0.01
A flaw has been found in LiuMengxuan04 MiniCode 0.1.0. Affected by this vulnerability is the function child_process.spawn of the file mcp.ts. Executing a manipulation can lead to command injection. The attack can be launched remotely. The attack requires a high level of…
- risk 0.00cvss 9.1epss 0.01
An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component
- risk 0.00cvss 9.8epss 0.01
An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted HTML page.
- risk 0.00cvss 7.8epss 0.00
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.234, Tabby inserts dropped file paths from tabby-electron/src/pathDrop.ts into the active shell without neutralizing command substitution metacharacters such as $(…) and `…`, so the incomplete…
- risk 0.00cvss 8.8epss 0.01
Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network.
- risk 0.00cvss 6.3epss 0.01
Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampering over a network.
- risk 0.00cvss 7.8epss 0.00
Improper neutralization of special elements used in a command ('command injection') in Windows Clipboard User Service allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.8epss 0.00
Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 8.4epss 0.00
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 9.6epss 0.01
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 5.3epss 0.01
A vulnerability was found in louisho5 picobot up to 0.2.0. This issue affects the function ExecTool.Execute of the file internal/agent/tools/exec.go of the component exec Tool. The manipulation results in os command injection. The attack requires a local approach. The exploit…
- risk 0.00cvss —epss 0.01
The NPC start endpoint on the web server at port 8090 is vulnerable to command injection.
- risk 0.00cvss —epss 0.01
The network diagnosis endpoint on the web server at port 8090 is vulnerable to command injection.
- risk 0.00cvss 6.3epss 0.02
A weakness has been identified in Shibby Tomato up to 1.28.0000. This affects the function sub_2D048 of the component CIFS Mount Handler. Executing a manipulation of the argument cifs1/cifs2 can lead to os command injection. The attack can be executed remotely. The exploit has…