CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the <Command> tag text content inside <UserDef
RPG MAKER MV and MZ provided by Gotcha Gotcha Games Inc. contain an OS command injection vulnerability. If a user loads
A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the ope
gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.234, Tabby inserts dropped file paths
OS command injection in the npm package loading component in AWS jsii-diff before 1.131.0 might allow context-dependent
A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) a
A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) a
When importing connections in Compass it is possible to override some connection options that are otherwise can't be cha
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILG
NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of
A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.fil
A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user t
A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to ex
A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, re
A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary
A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to exec
@oblique/cli 15.4.0 contains an OS command injection vulnerability in the project creation functionality. The CLI constr
NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Vers
Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attacker to execute arbitrary code due to imp
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Com
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Com
In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible
Super Productivity is an advanced todo list app with integrated timeboxing and time tracking capabilities. Prior to 18.1
linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfa
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to shell me
The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13
Sony XAV-9500ES Crash Dump Handler Command Injection Local Privilege Escalation Vulnerability. This vulnerability allows
UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _run_comman
UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _command_co
UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the user substi
better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by interpolating the user-s
Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victi
A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted fil
NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could cause
NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacker could cause OS com
NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS
NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS comma
Greenshot is an open source Windows screenshot utility. Versions 1.3.310 and below arvulnerable to OS Command Injection
OpenClaw is a personal AI assistant. Prior to version 2026.1.29, there is an OS command injection vulnerability via the
WPGraphQL provides a GraphQL API for WordPress sites. Prior to version 2.9.1, the `wp-graphql/wp-graphql` repository con
Warp is an agentic development environment. From 0.2024.03.12.08.02.stable_01 until 0.2026.05.06.15.42.stable_01, Warp c
OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remo
OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attack
OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote att
OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows r
Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vul
ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
In openshift-metal3/fakefish there is a repeated pattern in some of the scripts where shell variables are injected with
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started