VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,573)

page 116 of 329
  • CVE-2026-45633CriMay 29, 2026
    risk 0.57cvss 9.9epss 0.01

    Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injection vulnerability in the /docker-container-logs WebSocket endpoint. The tail and since parameters are not validated and are directly concatenated into shell…

  • CVE-2026-45578HigMay 29, 2026
    risk 0.57cvss 8.8epss 0.00

    WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a classic shell-metacharacter injection. The YPTSocket notification branch in plugin/Live/on_publish.php builds an execAsync() command line by string concatenation, single-quoting each argument but never…

  • CVE-2026-9208HigMay 27, 2026
    risk 0.57cvss 8.8epss 0.00

    Tanium addressed an unauthorized code execution vulnerability in Connect.

  • CVE-2026-36044HigMay 27, 2026
    risk 0.57cvss 8.8epss 0.02

    @pensar/apex <= 0.0.58 is vulnerable to OS command injection via the smart_enumerate tool. The createSmartEnumerateTool() function in src/core/agent/tools.ts constructs a shell command by concatenating unsanitized values from the extensions array and url parameter into a string…

  • CVE-2026-9207HigMay 27, 2026
    risk 0.57cvss 8.8epss 0.00

    Tanium addressed an unauthorized code execution vulnerability in Connect.

  • CVE-2026-46624CriMay 26, 2026
    risk 0.57cvss 9.9epss 0.00

    Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in Twenty CRM via a chained SQL Injection and PostgreSQL COPY TO PROGRAM attack. If Postgres user is a super user then any authenticated user can execute…

  • CVE-2026-36828HigMay 19, 2026
    risk 0.57cvss 8.8epss 0.02

    A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint of Panabit PAP-XM320 up to and including v7.7. The CGI component allows authenticated users to execute arbitrary shell commands with root privileges via the action=runcmd parameter.

  • CVE-2026-37281CriMay 19, 2026
    risk 0.57cvss 9.8epss 0.02

    An OS command injection vulnerability in the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 allows remote attackers to execute arbitrary commands via the url parameter.

  • CVE-2026-27130CriMay 18, 2026
    risk 0.57cvss 9.9epss 0.01

    Dokploy is a free, self-hostable Platform as a Service (PaaS). Versions 0.26.6 and below have OS command injection through the appName parameter. 3 chained issues cause this problem: inadequate input sanitization, lack of schema validation and direct shell interpolation.…

  • CVE-2026-25244CriMay 18, 2026
    risk 0.57cvss 9.8epss 0.03

    WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium. Versions below 9.24.0 contain a command injection vulnerability leading to remote code execution (RCE) in test orchestration. Git permits branch names…

  • CVE-2026-8654HigMay 15, 2026
    risk 0.57cvss epss 0.00

    Improper input validation in Delphix Continuous Data connectors allows an authenticated user to execute arbitrary operating system commands on the staging or target host.

  • CVE-2026-26191CriMay 14, 2026
    risk 0.57cvss 9.8epss 0.01

    Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet's software installer pipeline could allow a crafted software package to execute arbitrary commands as root (macOS/Linux) or SYSTEM (Windows) on managed endpoints when an uninstall…

  • CVE-2026-41315CriMay 14, 2026
    risk 0.57cvss 9.8epss 0.01

    mdserver-web is a simple Linux panel. From 0.18.0 to 0.18.4, mdserver-web has a front-end unauthorized remote command execution vulnerability. Due to the lack of authentication on the /modify_crond and /start_task interfaces, it is possible to modify the default built-in…

  • CVE-2026-42589CriMay 14, 2026
    risk 0.57cvss 9.8epss 0.03

    Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg's /forms/pdfengines/metadata/write HTTP endpoint accepts a JSON metadata object and passes its keys directly to ExifTool via the go-exiftool library. No validation is performed on key…

  • CVE-2026-6281HigMay 13, 2026
    risk 0.57cvss 8.8epss 0.00

    A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user on the local network to execute arbitrary commands on the device.

  • CVE-2026-42924HigMay 13, 2026
    risk 0.57cvss 8.7epss 0.00

    An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects through iControl SOAP resulting in privilege escalation.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2026-34176HigMay 13, 2026
    risk 0.57cvss 8.7epss 0.01

    When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary.   Note: Software versions which have reached End of Technical…

  • CVE-2026-41613HigMay 12, 2026
    risk 0.57cvss 8.8epss 0.01

    Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-31226CriMay 12, 2026
    risk 0.57cvss 9.8epss 0.01

    The TinyZero project thru commit 6652a63c57fa7e5ccde3fc9c598c7176ff15b839 (2025-58-24) contains a critical command injection vulnerability (CWE-78) in its HDFS file operation utilities. The vulnerability arises from the unsafe construction and execution of shell commands via…

  • CVE-2026-7256HigMay 12, 2026
    risk 0.57cvss 8.8epss 0.01

    ** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the LAN to execute operating system (OS) commands on a vulnerable device by sending a crafted HTTP…