VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 283 of 324
  • CVE-2025-6193MedJun 20, 2025
    risk 0.38cvss 5.9epss 0.01

    A command injection vulnerability was discovered in the TrustyAI Explainability toolkit. Arbitrary commands placed in certain fields of a LMEValJob custom resource (CR) may be executed in the LMEvalJob pod's terminal. This issue can be exploited via a maliciously crafted…

  • CVE-2023-34980MedMar 8, 2024
    risk 0.38cvss 5.9epss 0.01

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following…

  • CVE-2023-6612MedDec 8, 2023
    risk 0.38cvss 5.5epss 0.31

    A vulnerability was found in Totolink X5000R 9.1.0cu.2300_B20230112. It has been rated as critical. This issue affects the function setDdnsCfg/setDynamicRoute/setFirewallType/setIPSecCfg/setIpPortFilterRules/setLancfg/setLoginPasswordCfg/setMacFilterRules/setMtknatCfg/setNetworkC…

  • CVE-2026-55410MedJul 15, 2026
    risk 0.37cvss 6.7epss 0.00

    NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.1.19, NocoBase @nocobase/plugin-backups restored PostgreSQL backups by interpolating the database.schema value from _metadata.json into shell command…

  • CVE-2026-44076MedMay 21, 2026
    risk 0.37cvss 6.7epss 0.00

    Insufficient sanitization of volume paths in Netatalk 3.1.0 through 4.4.2 allows a local privileged user to inject OS commands and execute arbitrary code via a crafted volume path.

  • CVE-2025-64340MedApr 3, 2026
    risk 0.37cvss 6.7epss 0.01

    FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, server names containing shell metacharacters (e.g., &) can cause command injection on Windows when passed to fastmcp install claude-code or fastmcp install gemini-cli. These install paths…

  • CVE-2026-33623MedMar 26, 2026
    risk 0.37cvss 6.7epss 0.03

    PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.8.4` contains a Windows-only command injection issue in the orphaned Chrome cleanup path. When an instance is stopped, the Windows cleanup routine builds a PowerShell…

  • CVE-2026-29607MedMar 19, 2026
    risk 0.37cvss 6.8epss 0.00

    OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in allow-always wrapper persistence that allows attackers to bypass approval checks by persisting wrapper-level allowlist entries instead of validating inner executable intent. Remote attackers…

  • CVE-2026-22169MedMar 18, 2026
    risk 0.37cvss 6.7epss 0.00

    OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safeBins configuration that allows attackers to invoke external helpers through the compress-program option. When sort is explicitly added to tools.exec.safeBins, remote attackers can bypass…

  • CVE-2026-2035MedFeb 20, 2026
    risk 0.37cvss 6.8epss 0.02

    Deciso OPNsense diag_backup.php filename Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Deciso OPNsense. Authentication is required to exploit this vulnerability. …

  • CVE-2025-12763MedNov 13, 2025
    risk 0.37cvss 6.8epss 0.01

    pgAdmin 4 versions up to 9.9 are affected by a command injection vulnerability on Windows systems. This issue is caused by the use of shell=True during backup and restore operations, enabling attackers to execute arbitrary system commands by providing specially crafted file path…

  • CVE-2024-58257MedAug 8, 2025
    risk 0.37cvss 5.7epss 0.00

    EnzoH has an OS command injection vulnerability. Successful exploitation of this vulnerability may lead to arbitrary command execution.

  • CVE-2025-5525MedJun 3, 2025
    risk 0.37cvss 5.6epss 0.03

    A vulnerability was found in Jrohy trojan up to 2.15.3. It has been declared as critical. This vulnerability affects the function LogChan of the file trojan/util/linux.go. The manipulation of the argument c leads to os command injection. The attack can be initiated remotely. The…

  • CVE-2025-48204MedMay 21, 2025
    risk 0.37cvss 6.8epss 0.01

    The ns_backup extension through 13.0.0 for TYPO3 allows command injection.

  • CVE-2024-44072MedSep 10, 2024
    risk 0.37cvss 5.7epss 0.01

    OS command injection vulnerability exists in BUFFALO wireless LAN routers and wireless LAN repeaters. If a user logs in to the management page and sends a specially crafted request to the affected product from the product's specific management page, an arbitrary OS command may…

  • CVE-2023-5684MedOct 21, 2023
    risk 0.37cvss 4.7epss 0.78

    A vulnerability was found in Byzoro Smart S85F Management Platform up to 20231012. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /importexport.php. The manipulation leads to os command injection. The attack can be…

  • CVE-2020-21583MedAug 22, 2023
    risk 0.37cvss 6.7epss 0.01

    An issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated privlidges or execute arbitrary commands via the path parameter when setting the date.

  • CVE-2022-1359MedMay 17, 2022
    risk 0.37cvss 5.7epss 0.01

    The affected On-Premise cnMaestro is vulnerable to an arbitrary file-write through improper limitation of a pathname to a restricted directory inside a specific route. If an attacker supplied path traversal charters (../) as part of a filename, the server will save the file…

  • CVE-2022-0764MedFeb 26, 2022
    risk 0.37cvss 6.7epss 0.01

    Arbitrary Command Injection in GitHub repository strapi/strapi prior to 4.1.0.

  • CVE-2018-11805MedDec 12, 2019
    risk 0.37cvss 6.7epss 0.01

    In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA 3.4.3, we recommend that users should only use update…