CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function async_run_command of the file src/openllm
A vulnerability was determined in AidanPark openclaw-android up to 0.4.0. The affected element is an unknown function of
A vulnerability was found in louisho5 picobot up to 0.2.0. This issue affects the function ExecTool.Execute of the file
A vulnerability was identified in jsforce up to 3.10.16. This issue affects the function _execCommand in the library lib
A vulnerability was detected in oclif up to 4.23.16. Affected by this vulnerability is the function child_process.exec o
A vulnerability was identified in danger danger-js up to 13.0.7. Impacted is the function danger.git.diffForFile of the
A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the funct
A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/p
A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell.
A security vulnerability has been detected in release-it conventional-changelog up to 11.0.1. This affects the function
A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected element is an unknown funct
A flaw has been found in jiantao88 android-mcp-server up to cfb872b2446794193b58edd63f4dbf6af48a6292. The impacted eleme
A vulnerability was detected in sworddut mcp-ffmpeg-helper 0.1.0/0.1.1/0.2.1. This affects the function handleToolCall o
The Okta Privileged Access client does not reject a leading hyphen in the username portion of an SSH target. As a result
A security flaw has been discovered in AlexGladkov claude-in-mobile 3.10.2. This affects the function execSync of the fi
A vulnerability has been found in vercel ai up to 3.0.97. Impacted is the function run of the file .github/workflows/pre
Vowpal Wabbit is a machine learning system. The workflow .github/workflows/python_checks.yml embeds ${{ github.event.pul
Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded i
A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. This vulnerability affects the function subprocess.Po
A vulnerability was determined in D-Link DIR-823X 250416. Affected by this issue is the function sub_424D20 of the file
A security flaw has been discovered in D-Link DIR-823X 250416. This vulnerability affects unknown code of the file /gofo
A vulnerability was determined in D-Link DIR-823X 250416. The affected element is an unknown function of the file /gofor
A vulnerability was identified in D-Link DIR-823X 250416. The impacted element is an unknown function of the file /gofor
A vulnerability was identified in DrayTek Vigor 300B up to 1.5.1.6. This affects the function cgiGetFile of the file /cg
A security flaw has been discovered in Tenda AC8 16.03.50.11. This affects the function route_set_user_policy_rule of th
A weakness has been identified in kalcaddle kodbox 1.64. This affects the function checkBin of the file /workspace/sourc
A vulnerability has been found in Tenda AC6 2.0/15.03.06.23. The affected element is an unknown function of the file /go
A security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01. Affected is the function fromSetWirelessRepeat
A security vulnerability has been detected in Tenda AC6 15.03.06.23. Affected by this issue is the function get_log_file
A vulnerability was identified in D-Link DNS-320 2.06B01. The impacted element is the function cgi_speed/cgi_dhcpd_lease
A security flaw has been discovered in D-Link DNS-320 2.06B01. This affects the function delete/rename/copy/move/chmod/c
A weakness has been identified in D-Link DNS-320 2.06B01. This impacts the function cgi_set_host/cgi_set_ntp/cgi_fan_con
ToolJet is an open-source low-code platform for building internal tools. Prior to 3.20.180, ToolJet's render preview dep
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privilege
MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain an incomplete fix for CVE-2025-539
A Potential Command Injection vulnerability in HCL AION. An This can allow unintended command execution, potentially
Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by
A vulnerability was found in TanStack devtools-vite 0.7.0. Affected by this issue is the function installPackage of the
Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists
OpenClaw versions prior to 2026.2.19 tools.exec.safeBins contains an input validation bypass vulnerability that allows a
Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists
Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp a
A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metachara
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimu
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.451
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Netatalk 2.2.1 through 4.4.2 calls system() after a failed chdir() without properly handling the error condition, which
Kieback&Peter Neutrino-GLT product is used for building management. It's web component "SM70 PHWEB" is vulnerable to she
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started