VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,524)

page 248 of 327
  • CVE-2026-35043HigApr 6, 2026
    risk 0.44cvss 7.8epss 0.00

    BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.38, the cloud deployment path in src/bentoml/_internal/cloud/deployment.py was not included in the fix for CVE-2026-33744. Line 1648 interpolates…

  • CVE-2026-31067MedApr 6, 2026
    risk 0.44cvss 6.8epss 0.00

    A remote command execution (RCE) vulnerability in the /goform/formReleaseConnect component of UTT Aggressive 520W v3v1.7.7-180627 allows attackers to execute arbitrary commands via a crafted string.

  • CVE-2026-0596HigMar 31, 2026
    risk 0.44cvss 7.8epss 0.01

    A command injection vulnerability exists in mlflow/mlflow when serving a model with `enable_mlserver=True`. The `model_uri` is embedded directly into a shell command executed via `bash -c` without proper sanitization. If the `model_uri` contains shell metacharacters, such as…

  • CVE-2026-33874HigMar 27, 2026
    risk 0.44cvss 7.8epss 0.00

    Gematik Authenticator securely authenticates users for login to digital health applications. Starting in version 4.12.0 and prior to version 4.16.0, the Mac OS version of the Authenticator is vulnerable to remote code execution, triggered when victims open a malicious file.…

  • CVE-2026-32948HigMar 24, 2026
    risk 0.44cvss 7.8epss 0.00

    sbt is a build tool for Scala, Java, and others. From version 0.9.5 to before version 1.12.7, on Windows, sbt uses Process("cmd", "/c", ...) to run VCS commands (git, hg, svn). The URI fragment (branch, tag, revision) is user-controlled via the build definition and passed to…

  • CVE-2026-22902MedMar 20, 2026
    risk 0.44cvss 6.7epss 0.00

    A command injection vulnerability has been reported to affect QuNetSwitch. If a local attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuNetSwitch…

  • CVE-2026-32032HigMar 19, 2026
    risk 0.44cvss 7.8epss 0.00

    OpenClaw versions prior to 2026.2.22 contain an arbitrary shell execution vulnerability in shell environment fallback that trusts the unvalidated SHELL path from the host environment. An attacker with local environment access can inject a malicious SHELL variable to execute…

  • CVE-2026-3227MedMar 16, 2026
    risk 0.44cvss 6.8epss 0.01

    A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command. In the router configuration import function allows an authenticated attacker to upload a crafted…

  • CVE-2026-29783HigMar 6, 2026
    risk 0.44cvss 7.8epss 0.00

    The shell tool within GitHub Copilot CLI versions prior to and including 0.0.422 can allow arbitrary code execution through crafted bash parameter expansion patterns. An attacker who can influence the commands executed by the agent (e.g., via prompt injection through repository…

  • CVE-2026-20099MedFeb 25, 2026
    risk 0.44cvss 6.7epss 0.01

    A vulnerability in the web-based management interface of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker with administrative privileges to perform command injection attacks on an affected system and elevate privileges…

  • CVE-2026-25933MedFeb 12, 2026
    risk 0.44cvss 6.8epss 0.00

    Arduino App Lab is a cross-platform IDE for developing Arduino Apps. Prior to 0.4.0, a vulnerability was identified in the Terminal component of the arduino-app-lab application. The issue stems from insufficient sanitization and validation of input data received from connected…

  • CVE-2026-25546HigFeb 4, 2026
    risk 0.44cvss 7.8epss 0.01

    Godot MCP is a Model Context Protocol (MCP) server for interacting with the Godot game engine. Prior to version 0.1.1, a command injection vulnerability in godot-mcp allows remote code execution. The executeOperation function passed user-controlled input (e.g., projectPath)…

  • CVE-2026-25143HigFeb 4, 2026
    risk 0.44cvss 7.8epss 0.00

    melange allows users to build apk packages using declarative pipelines. From version 0.10.0 to before 0.40.3, an attacker who can influence inputs to the patch pipeline could execute arbitrary shell commands on the build host. The patch pipeline in pkg/build/pipelines/patch.yaml…

  • CVE-2026-24844HigFeb 4, 2026
    risk 0.44cvss 7.9epss 0.00

    melange allows users to build apk packages using declarative pipelines. From version 0.3.0 to before 0.40.3, an attacker who can provide build input values, but not modify pipeline definitions, could execute arbitrary shell commands if the pipeline uses ${{vars.*}} or…

  • CVE-2026-24905HigJan 29, 2026
    risk 0.44cvss 7.8epss 0.01

    Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. The `ig` binary provides a subcommand for image building, used to generate custom gadget OCI images. A part of this functionality is…

  • CVE-2026-22718MedJan 14, 2026
    risk 0.44cvss 6.8epss 0.01

    The VSCode extension for Spring CLI are vulnerable to command injection, resulting in command execution on the users machine.

  • CVE-2025-37158MedNov 18, 2025
    risk 0.44cvss 6.7epss 0.01

    A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to conduct a Remote Code Execution (RCE) on the affected system.

  • CVE-2025-37157MedNov 18, 2025
    risk 0.44cvss 6.7epss 0.01

    A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to conduct a Remote Code Execution (RCE) on the affected system.

  • CVE-2025-55055MedNov 17, 2025
    risk 0.44cvss 6.8epss 0.01

    CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

  • CVE-2025-42892MedNov 11, 2025
    risk 0.44cvss 6.8epss 0.01

    Due to an OS Command Injection vulnerability in SAP Business Connector, an authenticated attacker with administrative access and adjacent network access could upload specially crafted content to the server. If processed by the application, this content enables execution of…