Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Li
DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags. DataDog::DogStatsd does not
OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN opt
DataDog::DogStatsd versions through 0.07 for Perl allow metric injections. DataDog::DogStatsd does not properly sanitis
Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections. The statsd p
Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for th
Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to p
Net::Statsd::Tiny versions before 0.3.8 for Perl allowed metric injections. The metric names and set values were not ch
Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injections. The statsd prot
Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to sanitize user-cont
Tanium addressed an unauthorized code execution vulnerability in Tanium Appliance.
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, since Tabby does not escape cont
Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.3, kitty's OSC 21 (color-control) query reply re
Etsy::StatsD versions through 1.002002 for Perl allow metric injections. The metric names and values are not checked fo
App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output m
Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose inf
Net::Statsd::Lite versions through 0.10.0 for Perl allowed metric injections. The values from the set_add method were n
Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb
An improper neutralization of escape, meta, or control sequences vulnerability has been reported to affect QHora. If a l
In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a
Net::Statsd::Lite versions before 0.9.0 for Perl allowed metric injections. The metric names were not checked for newli
Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections. The metric names are not checked fo
Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injections. The statsd pr
http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It
Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, write(s rune
badkeys is a tool and library for checking cryptographic public keys for known vulnerabilities. In versions 0.0.15 and b
Mailpit is an email testing tool and API for developers. Prior to version 1.28.3, Mailpit's SMTP server is vulnerable to
Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections. The metric names and set values w
Net::Statsd versions before 0.13 for Perl allow metric injections. The metric names are not checked for newlines, colon
Claude HUD through 0.0.12, patched in commit 234d9aa, constructs OSC 8 terminal hyperlink escape sequences using raw cwd
broot renders each file and directory name in its interactive tree view exactly as read from the filesystem. Names are c
Bash-it 3.2.0 contains a terminal escape sequence injection vulnerability in the barbuk theme's Python virtualenv prompt
OpenClaw versions 2026.2.13 through 2026.3.24 contain an ANSI escape sequence injection vulnerability in approval prompt
npm-check-updates through 23.0.2, fixed in commit b554b84, contains a terminal escape sequence injection vulnerability t
`gh` is GitHub’s official command line tool. From 1.6.0 to before 2.92.0, a security vulnerability has been identified i
MuPDF before 1.27 contains an ANSI injection vulnerability in mutool that allows attackers to inject arbitrary ANSI esca
powerlevel10k fails to neutralize control characters in the package.json version field when rendering the package prompt
GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, multiple GitHub CLI commands printed ex
Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/wind
Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/w
Frequently Asked Questions
What is CWE-150?
CWE-150 (CWE-150) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-150?
There are 40 CVE records associated with CWE-150 in our database. Of these, 7 are critical severity, 11 are high severity, and 16 are medium severity.
How can I protect against CWE-150 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-150 using AI-powered security agents.
Detect CWE-150 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-150 vulnerabilities across your infrastructure.
Get Started