VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,970)

page 192 of 199
  • CVE-2026-16492MedJul 22, 2026
    risk 0.00cvss 5.5epss 0.04

    A weakness has been identified in umijs umi up to 4.6.63. The affected element is the function git.getFileCreateInfo of the file packages/utils/src/getFileGitIno.ts of the component GIT File Helper. This manipulation causes os command injection. The exploit has been made…

  • CVE-2026-16489MedJul 22, 2026
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was identified in jsforce up to 3.10.16. This issue affects the function _execCommand in the library lib/registry/sfdx.js of the component SFDX Connection Registry. The manipulation leads to os command injection. The attack can only be performed from a local…

  • CVE-2026-16488MedJul 22, 2026
    risk 0.00cvss 5.0epss 0.01

    A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. This vulnerability affects the function subprocess.Popen of the file minicode/config.py of the component Project File Handler. Executing a manipulation can lead to os command injection. The attack may be launched…

  • CVE-2026-47690HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.01

    MeltanoHub is the source code for hub.meltano.com, the central place for Meltano plugins. Versions of the repo prior to commit 923820de8f64d753951fbbd54f7282a3d5f75173 were vulnerable to exfiltration of `GITHUB_TOKEN` with write permissions to the repository. The vulnerable…

  • CVE-2026-44879HigJul 21, 2026
    risk 0.00cvss 7.2epss 0.02

    A vulnerability in the command line interface of ECOS devices could allow a highly privileged, authenticated remote attacker to perform command injection on certain CLI commands. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying…

  • CVE-2026-16448MedJul 21, 2026
    risk 0.00cvss 6.3epss 0.01

    A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The affected element is…

  • CVE-2026-16133MedJul 18, 2026
    risk 0.00cvss 5.0epss 0.01

    A flaw has been found in LiuMengxuan04 MiniCode 0.1.0. Affected by this vulnerability is the function child_process.spawn of the file mcp.ts. Executing a manipulation can lead to command injection. The attack can be launched remotely. The attack requires a high level of…

  • CVE-2026-52199CriJul 17, 2026
    risk 0.00cvss 9.1epss 0.01

    An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component

  • CVE-2025-65720CriJul 15, 2026
    risk 0.00cvss 9.8epss 0.01

    An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted HTML page.

  • CVE-2026-46709HigJul 15, 2026
    risk 0.00cvss 7.8epss 0.00

    Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.234, Tabby inserts dropped file paths from tabby-electron/src/pathDrop.ts into the active shell without neutralizing command substitution metacharacters such as $(…) and `…`, so the incomplete…

  • CVE-2026-56197HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network.

  • CVE-2026-55145MedJul 14, 2026
    risk 0.00cvss 6.3epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampering over a network.

  • CVE-2026-50488HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper neutralization of special elements used in a command ('command injection') in Windows Clipboard User Service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-58635HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

  • CVE-2026-50520HigJul 14, 2026
    risk 0.00cvss 8.4epss 0.00

    Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute code locally.

  • CVE-2026-48561CriJul 14, 2026
    risk 0.00cvss 9.6epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-15669MedJul 14, 2026
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was found in louisho5 picobot up to 0.2.0. This issue affects the function ExecTool.Execute of the file internal/agent/tools/exec.go of the component exec Tool. The manipulation results in os command injection. The attack requires a local approach. The exploit…

  • CVE-2026-22103CriJul 13, 2026
    risk 0.00cvss —epss 0.01

    The NPC start endpoint on the web server at port 8090 is vulnerable to command injection.

  • CVE-2026-22095CriJul 13, 2026
    risk 0.00cvss —epss 0.01

    The network diagnosis endpoint on the web server at port 8090 is vulnerable to command injection.

  • CVE-2026-15547MedJul 13, 2026
    risk 0.00cvss 6.3epss 0.02

    A weakness has been identified in Shibby Tomato up to 1.28.0000. This affects the function sub_2D048 of the component CIFS Mount Handler. Executing a manipulation of the argument cifs1/cifs2 can lead to os command injection. The attack can be executed remotely. The exploit has…