CWE-77

High likelihood

Improper Neutralization of Special Elements used in a Command ('Command Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

3,629 vulnerabilities with CWE-77
CVE-2026-7849 CRITICAL
Phoenix Contact CHARX SEC-3150 - Command Injection in SCM (idledisconnect Parameter)
CVSS 9.8
CVE-2026-54680 CRITICAL
Logging operator has Fluentd configuration injection that allows remote code execution
CVSS 9.9
CVE-2026-16763 MEDIUM
localstack serverless-localstack Configuration index.js os command injection
CVSS 5.3
CVE-2026-47670 CRITICAL
DbGate Vulnerable to Authenticated Remote Code Execution via loadReader functionName code injection
CVE-2026-16735 MEDIUM
release-it conventional-changelog Changelog File index.js writeChangelog os command injection
CVSS 5.3
CVE-2026-16733 MEDIUM
bahmutov find-cypress-specs Branch index.js shell.exec os command injection
CVSS 5.3
CVE-2026-16631 MEDIUM
publint package-manager pack.js child_process.exec os command injection
CVSS 5.3
CVE-2026-16630 MEDIUM
syncfusion ej2-javascript-ui-controls package.json child_process.exec os command injection
CVSS 5.3
CVE-2026-16629 MEDIUM
danger danger-js CLI localGetFileAtSHA.ts danger.git.diffForFile os command injection
CVSS 5.3
CVE-2026-16628 MEDIUM
oclif JIT Plugin Entry child_process.exec os command injection
CVSS 5.3
CVE-2026-16492 MEDIUM
umijs umi GIT File Helper getFileGitIno.ts git.getFileCreateInfo os command injection
CVSS 5.5
CVE-2026-16489 MEDIUM
jsforce SFDX Connection Registry sfdx.js _execCommand os command injection
CVSS 5.3
CVE-2026-16488 MEDIUM
QUSETIONS MiniCode-Python Project File config.py subprocess.Popen os command injection
CVSS 5.0
CVE-2026-47708 CRITICAL
MCP-for-Stata: Command injection via log_file_name parameter in Stata command wrapper
CVE-2026-47690 HIGH
MeltanoHub vulnerable to command injection in the `test_dispatcher` GitHub Actions workflow
CVSS 7.5
CVE-2026-44879 HIGH
Authenticated Command Injection allows arbitrary command execution in CLI Interface
CVSS 7.2
CVE-2026-16448 MEDIUM
D-Link DNS-1550-04 remote_backup.cgi cgi_check_rsync_rw command injection
CVSS 6.3
CVE-2026-59846 LOW
Libssh: libssh: information disclosure via proxycommand %r username expansion
CVSS 3.9
CVE-2026-16133 MEDIUM
LiuMengxuan04 MiniCode mcp.ts child_process.spawn command injection
CVSS 5.0
CVE-2026-52199 CRITICAL
Generic OEM UZ801_v2.1 4G LTE Router 3.4.3 - Remote Code Execution via sbin/adbd Component
CVSS 9.1
CVE-2026-30623 CRITICAL
LiteLLM 1.18.10 - Remote Code Execution via MCP Server Command Injection
CVSS 9.8
CVE-2026-46709 HIGH
Tabby < 1.0.234 - Drag-and-Drop Path Command Injection
CVSS 7.8
CVE-2026-56197 HIGH
Windows Admin Center (WAC) Remote Code Execution Vulnerability
CVSS 8.8
CVE-2026-55145 MEDIUM
Microsoft Copilot - Outlook Copilot Tampering Vulnerability
CVSS 6.3
CVE-2026-50488 HIGH
Microsoft Windows 11 Version 24H2 - Clipboard User Service Elevation of Privilege Vulnerability
CVSS 7.8
Details
Vulnerabilities 3,629
Exploit Likelihood High