← Back
CWE-78

6,733 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

JSON object

Loading...

CVEs (6,733)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Moodle
1Moodle
Jun 17, 2026
Mar 11, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.
1Icewhale
1Casaos
Jun 17, 2026
Mar 10, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CasaOS before v0.2.7 was discovered to contain a command injection vulnerability.
1Stripe
1Stripe Cli
Jun 17, 2026
Mar 9, 2022
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
Stripe CLI is a command-line tool for the Stripe eCommerce platform. A vulnerability in Stripe CLI exists on Windows when certain commands are run in a directory where an attacker has planted files. The commands are `str...Show more
Stripe CLI is a command-line tool for the Stripe eCommerce platform. A vulnerability in Stripe CLI exists on Windows when certain commands are run in a directory where an attacker has planted files. The commands are `stripe login`, `stripe config -e`, `stripe community`, and `stripe open`. MacOS and Linux are unaffected. An attacker who successfully exploits the vulnerability can run arbitrary code in the context of the current user. The update addresses the vulnerability by throwing an error in these situations before the code can run.Users are advised to upgrade to version 1.7.13. There are no known workarounds for this issue.Show less
1Genieacs
1Genieacs
Jun 17, 2026
Mar 6, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In GenieACS 1.2.x before 1.2.8, the UI interface API is vulnerable to unauthenticated OS command injection via the ping host argument (lib/ui/api.ts and lib/ping.ts). The vulnerability arises from insufficient input vali...Show more
In GenieACS 1.2.x before 1.2.8, the UI interface API is vulnerable to unauthenticated OS command injection via the ping host argument (lib/ui/api.ts and lib/ping.ts). The vulnerability arises from insufficient input validation combined with a missing authorization check.Show less
1Tp Link
1Archer C20i Firmware
Jun 17, 2026
Mar 4, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
There is remote authenticated OS command injection on TP-Link Archer C20i 0.9.1 3.2 v003a.0 Build 170221 Rel.55462n devices vie the X_TP_ExternalIPv6Address HTTP parameter, allowing a remote attacker to run arbitrary com...Show more
There is remote authenticated OS command injection on TP-Link Archer C20i 0.9.1 3.2 v003a.0 Build 170221 Rel.55462n devices vie the X_TP_ExternalIPv6Address HTTP parameter, allowing a remote attacker to run arbitrary commands on the router with root privileges.Show less
1Part Db Project
1Part Db
Jun 17, 2026
Mar 4, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
OS Command Injection in GitHub repository part-db/part-db prior to 0.5.11.
1Shescape Project
1Shescape
Jun 17, 2026
Mar 3, 2022
N/A· v4
5.5 MEDIUM· v3
1.9 LOW· v2
Shescape is a shell escape package for JavaScript. An issue in versions 1.4.0 to 1.5.1 allows for exposure of the home directory on Unix systems when using Bash with the `escape` or `escapeAll` functions from the _shesca...Show more
Shescape is a shell escape package for JavaScript. An issue in versions 1.4.0 to 1.5.1 allows for exposure of the home directory on Unix systems when using Bash with the `escape` or `escapeAll` functions from the _shescape_ API with the `interpolation` option set to `true`. Other tested shells, Dash and Zsh, are not affected. Depending on how the output of _shescape_ is used, directory traversal may be possible in the application using _shescape_. The issue was patched in version 1.5.1. As a workaround, manually escape all instances of the tilde character (`~`) using `arg.replace(/~/g, "\\~")`.Show less
1Npm Lockfile Project
1Npm Lockfile
Jun 17, 2026
Mar 3, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
OS Command Injection in GitHub repository ljharb/npm-lockfile in v2.0.3 and v2.0.4.
1Fortinet
1Fortiap C
Jun 17, 2026
Mar 2, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] in FortiAP-C console 5.4.0 through 5.4.3, 5.2.0 through 5.2.1 may allow an authenticated attacker to execute unauthorized comman...Show more
An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] in FortiAP-C console 5.4.0 through 5.4.3, 5.2.0 through 5.2.1 may allow an authenticated attacker to execute unauthorized commands by running CLI commands with specifically crafted arguments.Show less
1Fortinet
1Fortiwlm
Jun 17, 2026
Mar 1, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.2 and below, version 8.5.2 and below, version 8.4.2 and below, version 8.3.2 and below allows...Show more
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.2 and below, version 8.5.2 and below, version 8.4.2 and below, version 8.3.2 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests to the alarm dashboard and controller config handlers.Show less
1Zyxel
1Nwa1100 Nh Firmware
Jun 17, 2026
Mar 1, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS commands on the device.
1Moica
1Hicos
Jun 17, 2026
Mar 1, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Hicos citizen certificate client-side component does not filter special characters for command parameters in specific web URLs. An unauthenticated remote attacker can exploit this vulnerability to perform command injecti...Show more
Hicos citizen certificate client-side component does not filter special characters for command parameters in specific web URLs. An unauthenticated remote attacker can exploit this vulnerability to perform command injection attack to execute arbitrary system command, disrupt system or terminate service.Show less
1Strapi
1Strapi
Jun 17, 2026
Feb 26, 2022
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
Arbitrary Command Injection in GitHub repository strapi/strapi prior to 4.1.0.
1Jetbrains
1Teamcity
Jun 17, 2026
Feb 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
JetBrains TeamCity before 2021.2.3 was vulnerable to OS command injection in the Agent Push feature configuration.
1Tp Link
1Tl Wr840n Firmware
Jul 9, 2026
Feb 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.
1Tp Link
1Tl Wr840n Firmware
Jul 9, 2026
Feb 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.
1Tp Link
1Tl Wr840n Firmware
Jul 9, 2026
Feb 25, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.
1Google
1Fscrypt
Jun 17, 2026
Feb 25, 2022
N/A· v4
7.3 HIGH· v3
7.2 HIGH· v2
The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user who has control over mountpoint paths co...Show more
The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user who has control over mountpoint paths could potentially escalate their privileges if they create a malicious mountpoint path and if the system administrator happens to be using the fscrypt bash completion script to complete mountpoint paths. We recommend upgrading to version 0.3.3 or aboveShow less
1Apache
1Airflow
Jun 17, 2026
Feb 25, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command Injection from the web UI.
1Totolink
1T6 Firmware
Jun 17, 2026
Feb 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TOTOLink T6 V5.9c.4085_B20190428 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.