CWE-77
MITRE ↗Improper Neutralization of Special Elements used in a Command (Command Injection)
LangChain-ChatChat 0.3.1 contains a remote code execution vulnerability in its MCP STDIO server configuration and execut
Agent Zero 0.9.8 contains a remote code execution vulnerability in its External MCP Servers configuration feature. The a
Command injection in the connect function in NietThijmen ShoppingCart 0.0.2 allows an attacker to execute arbitrary shel
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacke
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacke
OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacke
OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker
JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, plugin-shell's run_command wrapped
Zohocorp ManageEngine ADSelfService Plus version before 6525, DataSecurity Plus before 6264 and RecoveryManager Plus bef
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unau
GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and g
Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via
launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the in
A vulnerability was detected in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This iss
A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTi
Due to an OS Command Execution vulnerability in SAP Forecasting & Replenishment, an authenticated attacker with administ
A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.5.6, a prior patch aimed to block spawning Windows b
# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of pote
A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in th
VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this is
shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The
FastNetMon Community Edition through 1.2.9 contains a configuration injection vulnerability in the Juniper router integr
D-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution vulnerability in the flag parameter of msp_info, which can b
A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allow
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio
NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could
Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special eleme
A prompt injection vulnerability in Windsurf 1.9544.26 allows remote attackers to execute arbitrary commands on a victim
SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the
A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread.set_config of the f
NVIDIA UFM Enterprise contains a vulnerability in the plugin management API, where an authenticated user with low privil
This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicio
Delta Electronics DIAView has Command Injection vulnerability.
Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Li
Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an una
NVIDIA NeMo Framework for all platforms contains a vulnerability in the ASR Evaluator utility, where a user could cause
NVIDIA NeMo Framework for all platforms contains a vulnerability in a voice-preprocessing script, where malicious input
OpenClaw is a personal AI assistant. Prior to version 2026.2.15, OpenClaw embedded the current working directory (worksp
A command injection vulnerability in the szc script of the ccurtsinger/stabilizer repository allows remote attackers to
Dell ThinOS 10 versions prior to ThinOS 2602_10.0573, contain an Improper Neutralization of Special Elements used in a C
Improper neutralization of special elements in the authentication components in Amazon Athena ODBC driver before 2.1.0.0
Improper neutralization of special elements used in a command ('command injection') in Windows Snipping Tool allows an u
A security vulnerability has been detected in tufantunc ssh-mcp up to 1.5.0. The affected element is the function shell.
An issue in Lymphatus caesium-image-compressor All versions up to and including commit 02da2c6 allows a local attacker t
Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthoriz
Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14000, the Turborepo
A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vul
gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmo
Command injection in Raynet rvia version 12.6 Update 8 and previous versions allows adversaries to execute arbitrary cod
Frequently Asked Questions
What is CWE-77?
CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-77?
There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.
How can I protect against CWE-77 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.
Detect CWE-77 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.
Get Started