VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 305 of 324
  • CVE-2026-17497HigJul 26, 2026
    risk 0.00cvss 8.3epss 0.00

    NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run…

  • CVE-2026-65711HigJul 24, 2026
    risk 0.00cvss 7.2epss 0.02

    sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administrators to execute arbitrary commands as the web server process user by setting a malicious backup path and triggering a backup. The FileBackupService builds a tar…

  • CVE-2026-63732CriJul 23, 2026
    risk 0.00cvss 9.9epss 0.01

    9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation, a bypass of the LOCAL_ONLY network gate via a spoofed Host header, and unvalidated arguments passed to child_process.spawn()…

  • CVE-2026-16763MedJul 23, 2026
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected element is an unknown function of the file src/index.js of the component Configuration Handler. The manipulation of the argument custom.localstack.docker.compose_file leads to os command…

  • CVE-2026-6516CriJul 23, 2026
    risk 0.00cvss 10.0epss 0.05

    Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.

  • CVE-2026-16735MedJul 23, 2026
    risk 0.00cvss 5.3epss 0.01

    A security vulnerability has been detected in release-it conventional-changelog up to 11.0.1. This affects the function writeChangelog of the file index.js of the component Changelog File Handler. Such manipulation of the argument infile leads to os command injection. The attack…

  • CVE-2026-16287HigJul 23, 2026
    risk 0.00cvss 7.8epss 0.00

    Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-update allows OS Command Injection. This issue affects pardus-update: from 0.6.6 before 0.7.0.

  • CVE-2026-16630MedJul 22, 2026
    risk 0.00cvss 5.3epss 0.01

    A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the function child_process.exec of the file package.json. The manipulation leads to os command injection. An attack has to be approached locally. The exploit has been…

  • CVE-2026-16629MedJul 22, 2026
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was identified in danger danger-js up to 13.0.7. Impacted is the function danger.git.diffForFile of the file source/platforms/git/localGetFileAtSHA.ts of the component CLI. Such manipulation of the argument File leads to os command injection. The attack needs to…

  • CVE-2026-16628MedJul 22, 2026
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was detected in oclif up to 4.23.16. Affected by this vulnerability is the function child_process.exec of the component JIT Plugin Entry Handler. Performing a manipulation of the argument jitPlugins results in os command injection. The attack is only possible…

  • CVE-2026-14881HigJul 22, 2026
    risk 0.00cvss 7.8epss 0.00

    When importing connections in Compass it is possible to override some connection options that are otherwise can't be changed via connection form. In particular it is possible to provide a custom browser open command for OIDC auth flow that is usually can be set only globally via…

  • CVE-2026-65590CriJul 22, 2026
    risk 0.00cvss 9.8epss 0.00

    n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/computer-use package (sandboxing was applied only on macOS). Shell commands executed by the tool run without any filesystem or network restrictions, allowing…

  • CVE-2026-3821HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.00

    Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI. An authorized attacker can exploit SMASH’s input capability to compromise data integrity or launch a Denial-of-Service (DoS) attack against the BMC.

  • CVE-2026-16492MedJul 22, 2026
    risk 0.00cvss 5.5epss 0.02

    A weakness has been identified in umijs umi up to 4.6.63. The affected element is the function git.getFileCreateInfo of the file packages/utils/src/getFileGitIno.ts of the component GIT File Helper. This manipulation causes os command injection. The exploit has been made…

  • CVE-2026-16489MedJul 22, 2026
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was identified in jsforce up to 3.10.16. This issue affects the function _execCommand in the library lib/registry/sfdx.js of the component SFDX Connection Registry. The manipulation leads to os command injection. The attack can only be performed from a local…

  • CVE-2026-16488MedJul 22, 2026
    risk 0.00cvss 5.0epss 0.01

    A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. This vulnerability affects the function subprocess.Popen of the file minicode/config.py of the component Project File Handler. Executing a manipulation can lead to os command injection. The attack may be launched…

  • CVE-2026-30631CriJul 21, 2026
    risk 0.00cvss 9.8epss 0.01

    An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309ad96c2a71313 (2025-09-11) allowing attackers to execute arbitrary code via crafted path to `computer_write_file`.

  • CVE-2026-6952HigJul 21, 2026
    risk 0.00cvss 7.2epss 0.01

    A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.

  • CVE-2026-64625CriJul 20, 2026
    risk 0.00cvss 9.8epss 0.00

    AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command substitution via $() and backticks. Attackers can inject arbitrary OS commands through the Live plugin on_publish.php endpoint…

  • CVE-2026-63766CriJul 20, 2026
    risk 0.00cvss 9.8epss 0.02

    GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate unsanitized Gradio textbox values directly into shell commands executed with shell=True. Attackers can inject shell…