CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability. This occurs because the logfile
Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Li
gradle-completion provides Bash and Zsh completion support for Gradle. A command injection vulnerability was found in gr
Dell Unity, version(s) 5.5.2 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command
Dell UnityVSA, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command
A vulnerability in Brocade Fabric OS could allow an authenticated, local attacker with privileges to access the Bash she
melange allows users to build apk packages using declarative pipelines. From version 0.10.0 to before 0.40.3, an attacke
Godot MCP is a Model Context Protocol (MCP) server for interacting with the Godot game engine. Prior to version 0.1.1, a
A command injection vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local network
The shell tool within GitHub Copilot CLI versions prior to and including 0.0.422 can allow arbitrary code execution thro
A command injection vulnerability has been reported to affect several QNAP operating system versions. If an attacker gai
AWStats 8.0 is vulnerable to Command Injection via the open function
sbt is a build tool for Scala, Java, and others. From version 0.9.5 to before version 1.12.7, on Windows, sbt uses Proce
Gematik Authenticator securely authenticates users for login to digital health applications. Starting in version 4.12.0
A command injection vulnerability exists in mlflow/mlflow when serving a model with `enable_mlserver=True`. The `model_u
InfCode's terminal auto-execution module contains a critical command filtering vulnerability that renders its blacklist
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, Glances supports dynamic config
OS command injection in the browser-based authentication component in Amazon Athena ODBC driver before 2.0.5.1 on Linux
PraisonAI is a multi-agent teams system. Prior to version 1.5.90, run_python() in praisonai constructs a shell command s
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.
Fleet is open source device management software. Prior to 4.81.1, the Orbit agent's FileVault disk encryption key rotati
parseusbs before 1.9 contains an OS command injection vulnerability in parseUSBs.py where LNK file paths are passed unsa
parseusbs before 1.9 contains an OS command injection vulnerability where the volume listing path argument (-v flag) is
UAC (Unix-like Artifacts Collector) before 3.3.0-rc1 contains a command injection vulnerability in the placeholder subst
Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.8.1 contain a command injection vulnerab
radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function tha
Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection
radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted
radare2 prior to 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.7.9, a code
A command injection vulnerability in Cribl Edge for Linux versions 3.2.0 through 4.17.0 allows a local unprivileged user
A vulnerability chain in Cribl Edge for Windows before 4.17.1 allows a local authenticated user to escalate privileges t
protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.2.1 and 2.0.2, pbts invoked JSDoc by building a sh
A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vul
Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute
systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, pamusb-pinentry reads
claude-code-cache-fix is a cache optimization proxy for Claude Code. From 3.5.0 to before 3.5.2, tools/quota-statusline.
uniget is a universal installer and updater for (container) tools. Prior to 0.27.1, a command injection vulnerability ex
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Microsoft UFO tagged releas
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command
In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
The browserstack-cypress-cli is BrowserStack's CLI which allows users to run Cypress tests on BrowserStack. Versions pri
Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1)
Warp is an agentic development environment. From 0.2025.04.09.08.11.stable_00 until 0.2026.05.06.15.42.stable_01, Warp c
Warp is an agentic development environment. From 0.2024.02.20.08.01.stable_01 until 0.2026.05.06.15.42.stable_01, Warp c
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Neutralization of Special Ele
Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances KVM/QEMU monitoring engine
Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the <GUIConfig name="commandLineInterpreter">
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started