VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (7,045)

page 164 of 353
  • CVE-2022-23465HigDec 2, 2022
    risk 0.39cvss 7.1epss 0.00

    SwiftTerm is a Xterm/VT100 Terminal emulator. Prior to commit a94e6b24d24ce9680ad79884992e1dff8e150a31, an attacker could modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views…

  • CVE-2021-33493MedNov 22, 2021
    risk 0.39cvss 6.0epss 0.00

    The middleware component in OX App Suite through 7.10.5 allows Code Injection via Java classes in a YAML format.

  • CVE-2021-3583HigSep 22, 2021
    risk 0.39cvss 7.1epss 0.01

    A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template if the user is trying to put templates in multi-line YAML strings and the facts being handled do not routinely include special…

  • CVE-2026-55071higAug 12, 2026
    risk 0.38cvss epss

    ## Stata Command Injection via Unsanitized `package` in `ado_package_install` ### Summary The `ado_package_install` MCP tool in `stata-mcp` concatenates user-controlled input directly into a Stata command string without any validation or sanitization. An attacker who can…

  • CVE-2026-72718HigAug 10, 2026
    risk 0.38cvss epss 0.00

    goose is general-purpose AI agent that runs on your machine. Prior to 1.44.0, the `goose review` command runs the system `git` executable to gather the diff for review without stripping attacker-controlled Git configuration. A malicious repository whose `.git/config` sets…

  • CVE-2025-31365MedOct 14, 2025
    risk 0.38cvss 5.8epss 0.00

    An Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in FortiClientMac 7.4.0 through 7.4.3, 7.2.1 through 7.2.8 may allow an unauthenticated attacker to execute arbitrary code on the victim's host via tricking the user into visiting a malicious…

  • CVE-2024-48908MedAug 28, 2025
    risk 0.38cvss epss 0.00

    lychee link checking action checks links in Markdown, HTML, and text files using lychee. Prior to version 2.0.2, there is a potential attack of arbitrary code injection vulnerability in lychee-setup of the composite action at action.yml. This issue has been patched in version…

  • CVE-2024-28397MedJun 20, 2024
    risk 0.38cvss 5.3epss 0.05

    An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a crafted API call.

  • CVE-2024-33394MedMay 2, 2024
    risk 0.38cvss 5.9epss 0.00

    An issue in kubevirt kubevirt v1.2.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.

  • CVE-2021-21353MedMar 3, 2021
    risk 0.38cvss 6.8epss 0.04

    Pug is an npm package which is a high-performance template engine. In pug before version 3.0.1, if a remote attacker was able to control the `pretty` option of the pug compiler, e.g. if you spread a user provided object such as the query parameters of a request into the pug…

  • CVE-2020-7381MedSep 3, 2020
    risk 0.38cvss 5.8epss 0.01

    In Rapid7 Nexpose installer versions prior to 6.6.40, the Nexpose installer calls an executable which can be placed in the appropriate directory by an attacker with access to the local machine. This would prevent the installer from distinguishing between a valid executable…

  • CVE-2014-8677MedAug 31, 2017
    risk 0.38cvss 5.3epss 0.03

    The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and access to an existing database with a crafted name, or permissions to create arbitrary databases, or if PHP before 5.2 is being used, the configuration…

  • CVE-2026-39311MedMay 20, 2026
    risk 0.37cvss 6.8epss 0.00

    Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Versions 0.102.1 and prior contain a critical security flaw where lack of SVG sanitization combined with a disabled Content Security Policy (CSP) and a…

  • CVE-2026-1516MedApr 8, 2026
    risk 0.37cvss 5.7epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.0.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that in Code Quality reports could have allowed an authenticated user to leak IP addresses of users viewing the report via specially crafted…

  • CVE-2025-15616MedMar 27, 2026
    risk 0.37cvss 6.7epss 0.02

    Wazuh wazuh-agent and wazuh-manager versions 2.1.0 before 4.8.0 contain multiple shell injection and untrusted search path vulnerabilities that allow attackers to execute arbitrary commands through various components including logcollector configuration, maild SMTP server tags,…

  • CVE-2026-23946MedJan 22, 2026
    risk 0.37cvss 6.8epss 0.01

    Tendenci is an open source content management system built for non-profits, associations and cause-based sites. Versions 15.3.11 and below include a critical deserialization vulnerability in the Helpdesk module (which is not enabled by default). This vulnerability allows Remote…

  • CVE-2024-27766MedOct 17, 2024
    risk 0.37cvss 5.7epss 0.01

    An issue in MariaDB v.11.1 allows a remote attacker to execute arbitrary code via the lib_mysqludf_sys.so function. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.

  • CVE-2024-44744MedOct 1, 2024
    risk 0.37cvss 5.7epss 0.00

    An issue in Malwarebytes Premium Security v5.0.0.883 allows attackers to execute arbitrary code via placing crafted binaries into unspecified directories. NOTE: Malwarebytes argues that this issue requires admin privileges and that the contents cannot be altered by non-admin…

  • CVE-2024-36531MedJun 10, 2024
    risk 0.37cvss 5.7epss 0.00

    nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before are vulnerable to arbitrary code execution via the /admin/extensions/upload.php component.

  • CVE-2024-36361MedMay 24, 2024
    risk 0.37cvss 6.8epss 0.00

    Pug through 3.0.2 allows JavaScript code execution if an application accepts untrusted input for the name option of the compileClient, compileFileClient, or compileClientWithDependenciesTracked function. NOTE: these functions are for compiling Pug templates into JavaScript, and…