VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 304 of 324
  • CVE-2026-16022HigAug 5, 2026
    risk 0.00cvss 7.8epss 0.00

    @oblique/cli 15.4.0 contains an OS command injection vulnerability in the project creation functionality. The CLI constructs shell commands through string concatenation and executes them with execSync(). A user-controlled project-name argument is inserted into the shell command…

  • CVE-2026-67599HigAug 3, 2026
    risk 0.00cvss 7.2epss 0.02

    ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attackers to execute arbitrary commands by submitting unsanitized input through the filter parameter, which is interpolated directly into a shell command in File.php.…

  • CVE-2026-67608HigAug 3, 2026
    risk 0.00cvss 7.2epss 0.02

    Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injection vulnerability in action_audio.php that allows authenticated attackers to execute arbitrary operating system commands by passing an unsanitized pid parameter…

  • CVE-2026-67308CriAug 1, 2026
    risk 0.00cvss epss 0.00

    Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metacharacters into environment variables that are…

  • CVE-2026-16843HigJul 31, 2026
    risk 0.00cvss 7.2epss 0.01

    Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary…

  • CVE-2026-12940CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.01

    IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py where the DANGEROUS_ENV_VARS…

  • CVE-2026-22622HigJul 30, 2026
    risk 0.00cvss 8.8epss 0.00

    Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to elevate privileges resulting in unrestricted access to the device.

  • CVE-2026-22621HigJul 30, 2026
    risk 0.00cvss 8.3epss 0.01

    Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administrator to execute arbitrary commands within a restricted environment.

  • CVE-2026-44106HigJul 30, 2026
    risk 0.00cvss 7.8epss 0.00

    A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.

  • CVE-2026-44099HigJul 30, 2026
    risk 0.00cvss 7.8epss 0.00

    A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.

  • CVE-2026-44098HigJul 30, 2026
    risk 0.00cvss 8.6epss 0.01

    This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution of arbitrary commands as the limited user charx-oa. Charging could be interrupted.

  • CVE-2026-44096HigJul 30, 2026
    risk 0.00cvss 7.8epss 0.00

    A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, resulting in full system compromise.

  • CVE-2026-44095HigJul 30, 2026
    risk 0.00cvss 7.8epss 0.00

    A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.

  • CVE-2026-44093HigJul 30, 2026
    risk 0.00cvss 7.8epss 0.00

    A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.

  • CVE-2026-61376HigJul 28, 2026
    risk 0.00cvss 7.2epss 0.01

    ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

  • CVE-2026-59764HigJul 28, 2026
    risk 0.00cvss 7.2epss 0.01

    ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

  • CVE-2026-55578HigJul 27, 2026
    risk 0.00cvss 8.8epss 0.00

    Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, the terminal feature in Pheditor uses an incomplete character blocklist to sanitize user-supplied commands before passing them to shell_exec(). After the fix for…

  • CVE-2026-54540HigJul 27, 2026
    risk 0.00cvss 8.8epss 0.01

    Pheditor is a single-file editor and file manager written in PHP. Prior to version 2.0.5, there is an authenticated terminal command whitelist bypass. The terminal feature checks whether the submitted command starts with one of the configured TERMINAL_COMMANDS values, then…

  • CVE-2026-24252HigJul 27, 2026
    risk 0.00cvss 7.8epss 0.01

    NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead to code execution, data tampering, escalation of privileges and information disclosure.

  • CVE-2025-59172HigJul 27, 2026
    risk 0.00cvss epss 0.00

    Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vulnerability allowing an attacker to execute arbitrary code as root.