CWE-78
High likelihoodImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
6,220 vulnerabilities with CWE-78
CVE-2026-55427
HIGH
Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`
CVSS 8.3
CVE-2026-44454
HIGH
Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent
CVSS 8.1
CVE-2026-59800
CRITICAL
9Router < 0.4.44 - OS Command Injection via sudoPassword Parameter in Tailscale Install Endpoint
CVSS 9.8
CVE-2026-53479
HIGH
Dell PowerProtect Data Domain - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 7.2
CVE-2026-42201
LOW
Coolify: OS Command Injection via Database Credential Fields in Docker Compose Service Commands
CVSS 3.3
CVE-2026-34158
HIGH
Coolify: Command injection via single-quote breakout in Docker Compose custom commands
CVSS 8.8
CVE-2026-42143
HIGH
Coolify: OS Command Injection via Persistent Volume Names - Root RCE on Managed Servers
CVSS 8.8
CVE-2026-34168
HIGH
Coolify: Command injection via unsanitized persistent storage name in docker volume commands
CVSS 8.8
CVE-2026-34152
HIGH
Coolify: Command Injection via Newline in Pre/Post Deployment Commands (Heredoc Transport)
CVSS 8.8
CVE-2026-34149
LOW
Coolify: Authenticated Host-Level RCE via Unescaped Database Credentials in Backup Jobs
CVSS 3.3
CVE-2026-34058
HIGH
Coolify: OS Command Injection via Unmanaged Container Operations - Remote Code Execution
CVSS 8.8
CVE-2026-34057
HIGH
Coolify: Authenticated Remote Code Execution via Command Injection in Database Import Container Name
CVSS 8.8
CVE-2026-34035
HIGH
Coolify: Host RCE via Log Drain secret/env command injection
CVSS 8.8
CVE-2026-34034
HIGH
Coolify: Host RCE via Sentinel token injection
CVSS 8.8
CVE-2026-42204
HIGH
Coolify: Authenticated RCE via SHELL_SAFE_COMMAND_PATTERN regression → host root
CVSS 8.8
CVE-2026-42153
HIGH
Coolify: PostgreSQL Healthcheck Command Injection Allows Root Code Execution in Container
CVSS 8.8
CVE-2026-42148
LOW
Coolify: Command Injection via Unescaped Version String in Docker Build
CVSS 3.8
CVE-2026-34599
HIGH
Coolify: Authenticated Remote Code Execution in GetLogs Livewire Component
CVSS 8.8
CVE-2026-34153
HIGH
Coolify LocalFileVolume fs_path command injection enables RCE
CVSS 8.8
CVE-2026-34049
LOW
Coolify: Command Injection via unsanitized MongoDB collection names in database backup
CVSS 3.3
CVE-2026-34038
CRITICAL
Coolify authenticated remote command injection leading to RCE and secret exfiltration
CVSS 9.9
CVE-2026-55798
MEDIUM
Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
CVSS 4.5
CVE-2026-14802
HIGH
react create-react-app react-dev-utils openBrowser.js startBrowserProcess os command injection
CVSS 7.3
CVE-2026-12195
HIGH
Vesta - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-53478
HIGH
Dell PowerProtect Data Domain - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 7.2
Details
Vulnerabilities
6,220
Exploit Likelihood
High