CWE-150

Improper Neutralization of Escape, Meta, or Control Sequences

Parent: CWE-138 - Improper Neutralization of Special Elements

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as escape, meta, or control character sequences when they are sent to a downstream component.

68 vulnerabilities with CWE-150
CVE-2026-3108 HIGH
Terminal Escape Injection in mmctl Report Posts Command
CVSS 8.0
CVE-2026-25996 CRITICAL
Inspektor Gadget < 0.49.1 - Terminal Injection via Unsanitized eBPF Event Strings
CVSS 9.8
CVE-2026-21521 HIGH
Microsoft 365 Word Copilot - Information Disclosure via Improper Neutralization of Escape Sequences
CVSS 7.4
CVE-2026-23829 MEDIUM
Mailpit < 1.28.3 - SMTP Header Injection via RCPT TO and MAIL FROM Address Validation
CVSS 5.3
CVE-2026-21439 MEDIUM
badkeys < 0.0.16 - Terminal Output Injection via ANSI Escape Sequences
CVSS 5.3
CVE-2025-62845 MEDIUM
QNAP QuRouter < 2.6.3.009 - Local Admin Control Sequence Injection
CVSS 6.7
CVE-2025-15311 HIGH
Tanium TanOS < 1.8.3.0146 - Unauthenticated Remote Code Execution
CVSS 7.8
CVE-2025-65082 MEDIUM
Apache HTTP Server 2.4.0-2.4.65 - Environment Variable Injection via CGI Configuration
CVSS 6.5
CVE-2025-64494 MEDIUM
Soft Serve <0.10.0 - Info Disclosure
CVSS 4.6
CVE-2025-55754 CRITICAL
Apache Tomcat 11.0.0-M1-11.0.10, 10.1.0-M1-10.1.44, 9.0.40-9.0.108 - ANSI Escape Sequence Injection
CVSS 9.6
CVE-2025-58160 LOW
tracing-subscriber < 0.3.20 - ANSI Escape Sequence Injection in Terminal Output
CVE-2025-55193 LOW
Active Record <7.1.5.2, <7.2.2.2, <8.0.2.1 - Info Disclosure
CVE-2025-47284 CRITICAL
Gardener <1.116.4, 1.117.5, 1.118.2, 1.119.0 - Privilege Escalation
CVSS 9.9
CVE-2025-30089 MEDIUM
gurk < 0.6.3 - ANSI Escape Sequence Injection
CVSS 5.4
CVE-2025-0975 HIGH
IBM MQ Appliance 9.3.0-9.3.0.26 and 9.4.0-9.4.1 - Authenticated Remote Code Execution via Escape Character Injection
CVSS 8.8
CVE-2025-1693 LOW
mongodb mongosh < 2.3.9 - Control Character Injection via Cluster Output
CVSS 3.9
CVE-2025-1692 MEDIUM
MongoDB Shell <2.3.9 - Code Injection
CVSS 6.3
CVE-2025-25286 CRITICAL
Islandora Crayfish < 4.1.0 - Remote Code Execution via Homarus Convert Endpoint
CVSS 9.8
CVE-2025-23026 MEDIUM
jte < 3.1.16 - Cross-Site Scripting via Unescaped JavaScript Template Strings
CVSS 6.1
CVE-2024-47252 HIGH
Apache HTTP Server <2.4.63 - Info Disclosure
CVSS 7.5
CVE-2024-58251 LOW
BusyBox < 1.37.0 - Denial of Service via ANSI Terminal Escape Sequence in netstat
CVSS 2.5
CVE-2024-52005 HIGH
Git < 2.40.4 - Terminal Control Sequence Injection via Sideband Channel
CVSS 8.8
CVE-2024-52006 HIGH
Git < 2.40.4 - Command Injection via Carriage Return Character
CVSS 7.5
CVE-2024-50349 MEDIUM
Git < 2.40.4 - Terminal Credential Prompt Spoofing via ANSI Escape Sequences
CVSS 4.7
CVE-2024-9774 MEDIUM
Python-SQL <unknown> - SQL Injection
CVSS 6.5
Details
Vulnerabilities 68