VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,573)

page 119 of 329
  • CVE-2026-33396CriMar 26, 2026
    risk 0.57cvss 9.9epss 0.01

    OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.35, a low-privileged authenticated user (ProjectMember) can achieve remote command execution on the Probe container/host by abusing Synthetic Monitor Playwright script execution. Synthetic…

  • CVE-2025-15101HigMar 26, 2026
    risk 0.57cvss 8.8epss 0.01

    An OS command injection vulnerability in the web management interface of certain ASUS router models allows remote authenticated administrators to execute arbitrary system commands via a crafted parameter. Refer to the 'Security Update for ASUS Router Firmware' section on the…

  • CVE-2026-3841HigMar 12, 2026
    risk 0.57cvss 8.8epss 0.02

    A command injection vulnerability has been identified in the Telnet command-line interface (CLI) of TP-Link TL-MR6400 v5.3. This issue is caused by insufficient sanitization of data processed during specific CLI operations. An authenticated attacker with elevated privileges…

  • CVE-2026-31975CriMar 11, 2026
    risk 0.57cvss 9.8epss 0.03

    Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.25.0, OS Command Injection via WebSocket Shell. Both projectPath and initialCommand in server/index.js are taken directly from the WebSocket message payload…

  • CVE-2026-31854HigMar 11, 2026
    risk 0.57cvss 8.8epss 0.00

    Cursor is a code editor built for programming with AI. Prior to 2.0 ,if a visited website contains maliciously crafted instructions, the model may attempt to follow them in order to “assist” the user. When combined with a bypass of the command whitelist mechanism, such…

  • CVE-2026-20040HigMar 11, 2026
    risk 0.57cvss 8.8epss 0.00

    A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user arguments that are…

  • CVE-2026-28292CriMar 10, 2026
    risk 0.57cvss 9.8epss 0.01

    `simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through 3.32.2 that allows an attacker to bypass two prior CVE fixes (CVE-2022-25860 and CVE-2022-25912) and achieve full remote code execution on the host machine.…

  • CVE-2026-28470CriMar 5, 2026
    risk 0.57cvss 9.8epss 0.00

    OpenClaw versions prior to 2026.2.2 contain an exec approvals (must be enabled) allowlist bypass vulnerability that allows attackers to execute arbitrary commands by injecting command substitution syntax. Attackers can bypass the allowlist protection by embedding unescaped $()…

  • CVE-2026-28391CriMar 5, 2026
    risk 0.57cvss 9.8epss 0.01

    OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe metacharacters in allowlist-gated exec requests (non-default configuration), allowing attackers to bypass command approval restrictions. Remote attackers can craft command strings with shell…

  • CVE-2026-28774HigMar 4, 2026
    risk 0.57cvss 8.8epss 0.02

    An OS Command Injection vulnerability exists in the web-based Traceroute diagnostic utility of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver Web Management Interface version 101. An authenticated attacker can inject arbitrary shell…

  • CVE-2026-28773HigMar 4, 2026
    risk 0.57cvss 8.8epss 0.02

    The web-based Ping diagnostic utility (/IDC_Ping/main.cgi) in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite  Receiver Web Management Interface version 101 is vulnerable to OS Command Injection. The application insecurely parses the `IPaddr`…

  • CVE-2026-27965CriFeb 26, 2026
    risk 0.57cvss 9.9epss 0.00

    Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage location (e.g. an S3 bucket) can manipulate backup manifest files so that arbitrary code is later executed when that…

  • CVE-2026-27728CriFeb 25, 2026
    risk 0.57cvss 9.9epss 0.02

    OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.7, an OS command injection vulnerability in `NetworkPathMonitor.performTraceroute()` allows any authenticated project user to execute arbitrary operating system commands on the Probe…

  • CVE-2026-27626CriFeb 25, 2026
    risk 0.57cvss 9.9epss 0.01

    OliveTin gives access to predefined shell commands from a web interface. In versions up to and including 3000.10.0, OliveTin's shell mode safety check (`checkShellArgumentSafety`) blocks several dangerous argument types but not `password`. A user supplying a `password`-typed…

  • CVE-2026-23678HigFeb 24, 2026
    risk 0.57cvss 8.8epss 0.01

    Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain a command injection vulnerability in the traceroute diagnostic function of the affected device web management interface. By injecting the %1a character into the hostname parameter, an…

  • CVE-2025-13943HigFeb 24, 2026
    risk 0.57cvss 8.8epss 0.01

    A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.50(ABVY.7)C0 could allow an authenticated attacker to execute operating system (OS) commands on an affected device.

  • CVE-2025-70328HigFeb 23, 2026
    risk 0.57cvss 8.8epss 0.02

    TOTOLINK X6000R v9.4.0cu.1498_B20250826 contains an OS command injection vulnerability in the NTPSyncWithHost handler of the /usr/sbin/shttpd executable. The host_time parameter is retrieved via sub_40C404 and passed to a date -s shell command through CsteSystem. While the first…

  • CVE-2026-2630HigFeb 17, 2026
    risk 0.57cvss 8.8epss 0.01

    A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the underlying server where Tenable Security Center is hosted.

  • CVE-2025-70828HigFeb 17, 2026
    risk 0.57cvss 8.8epss 0.00

    An issue in Datart v1.0.0-rc.3 allows attackers to execute arbitrary code via the url parameter in the JDBC configuration

  • CVE-2025-65480HigFeb 11, 2026
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Pacom Unison Client 5.13.1. Authenticated users can inject malicious scripts in the Report Templates which are executed when certain script conditions are fulfilled, leading to Remote Code Execution.