VulnSea

CWE-78

CVEs classified under CWE-78, newest first.

727 CVEsRSS

CVE-2026-57282Medium· 5.0
3mo ago

Jenkins Git client Plugin has an OS command injection vulnerability on agents

Jenkins Git client Plugin has an OS command injection vulnerability on agents

▾ Sunlitjenkins-ci · org.jenkins-ci.plugins:git-clientEPSS 0.25%via GHSA
GHSA-jj69-4grx-fqj5Critical· 7.8
3mo ago

Duplicate Advisory: Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses

Duplicate Advisory: Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses

▾ Midnightgoogle-github-actions · google-github-actions/run-gemini-clivia GHSA
CVE-2026-12537High· 7.8⚖ disputed
3mo ago

Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker …

Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker …

▾ Twilightgoogle · gemini-cliEPSS 0.21%via NVD
GHSA-v772-658q-978pLow
3mo ago

Duplicate Advisory: ImageMagick: SVG-to-MVG Command Injection via coders/svg.c

Duplicate Advisory: ImageMagick: SVG-to-MVG Command Injection via coders/svg.c

▾ SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
CVE-2026-56379High· 8.1
3mo ago

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector G…

▾ Twilightimagemagick · imagemagickEPSS 1.6%via NVD
CVE-2026-55173High· 8.1
3mo ago

AVideo has an incomplete fix of CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sink

AVideo has an incomplete fix of CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sink

▾ Twilightwwbn · wwbn/avideoEPSS 3.4%via GHSA
CVE-2026-55441High· 8.6
3mo ago

Mise vulnerable to arbitrary command execution via task-include files in an untrusted, config-less repository

Mise vulnerable to arbitrary command execution via task-include files in an untrusted, config-less repository

▾ Twilightmise · miseEPSS 0.18%via GHSA
CVE-2026-55448Medium· 6.3
3mo ago

Mise's local credential_command executes untrusted config

Mise's local credential_command executes untrusted config

▾ Sunlitmise · miseEPSS 0.16%via GHSA
CVE-2026-46606High· 7.8
3mo ago

Glances is Vulnerable to Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vms/engines/virsh.py

Glances is Vulnerable to Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vms/engines/virsh.py

▾ Twilightglances · glancesEPSS 0.21%via GHSA
CVE-2026-54051Critical· 9.9
3mo ago

Network-AI: Improper Neutralization of Special Elements used in an OS Command

Network-AI: Improper Neutralization of Special Elements used in an OS Command

▾ Midnightnetwork-ai · network-aiEPSS 0.67%via GHSA
GHSA-wg5p-8h9p-3mr7High· 8.6
3mo ago

agent-coderag: Gradle Wrapper Execution During Dependency Discovery Enables Arbitrary Code Execution

agent-coderag: Gradle Wrapper Execution During Dependency Discovery Enables Arbitrary Code Execution

▾ Twilightagent-coderag · agent-coderagvia GHSA
GHSA-vcv2-r9jh-99m5High· 8.8
3mo ago

Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into execSync

Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into execSync

▾ Twilightagentic-flow · agentic-flowvia GHSA
CVE-2026-55849High
3mo ago

@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument

@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument

▾ Twilightcyclonedx · @cyclonedx/cyclonedx-npmEPSS 0.24%via GHSA
GHSA-c3xh-98xp-6qhfHigh
3mo ago

githubtoplanguages: Command Injection via Issue Title in Discord Notification Workflow

githubtoplanguages: Command Injection via Issue Title in Discord Notification Workflow

▾ Twilightgouef · gouef/githubtoplanguagesvia GHSA
GHSA-v847-hxxw-3pxgHigh· 7.8
3mo ago

PraisonAI recipe.run_stream skips dangerous-tool policy enforcement

PraisonAI recipe.run_stream skips dangerous-tool policy enforcement

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-w6h2-fr4q-xvxvHigh· 8.8
3mo ago

PraisonAI: Compute-bridged file tools allow shell command injection

PraisonAI: Compute-bridged file tools allow shell command injection

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-p75f-6fp4-p57wCritical· 9.8
3mo ago

PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai

PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai

▾ Midnightpraisonai · praisonaivia GHSA
GHSA-vjv9-7m7j-h833High· 8.8
3mo ago

npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining

npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-5jv7-2mjm-h6qjHigh· 8.8
3mo ago

npm PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining

npm PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-7qw2-w5rc-37x2High· 7.8
3mo ago

PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml

PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml

▾ Twilightpraisonai · praisonaivia GHSA
CVE-2026-53848Low· 4.3
3mo ago

OpenClaw: Exec allowlist could miss side effects from transparent command wrappers

OpenClaw: Exec allowlist could miss side effects from transparent command wrappers

▾ Sunlitopenclaw · openclawEPSS 0.31%via GHSA
CVE-2026-53855High· 8.1
3mo ago

OpenClaw: Shell positional parameters could weaken strict inline-eval checks

OpenClaw: Shell positional parameters could weaken strict inline-eval checks

▾ Twilightopenclaw · openclawEPSS 0.45%via GHSA
CVE-2026-0755Critical· 9.80day
3mo ago

gemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755)

gemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755)

▾ Hadalgemini-mcp-tool · gemini-mcp-toolEPSS 3.5%via GHSA
CVE-2026-55743Critical· 9.6
3mo ago

The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed to execute arbitrary OS commands with the privileges of the desktop user.

The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed to execute arbitrary OS commands with the privileges of the desktop user.

▾ MidnightEPSS 0.57%via NVD
CVE-2026-55748Medium· 6.0
3mo ago

OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters

OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types…

▾ Sunlitopenstack · horizonEPSS 0.46%via NVD
CVE-2026-12398High· 7.5
3mo ago

Galaxy NG: command injection vulnerability

Galaxy NG: command injection vulnerability

▾ Twilightgalaxy-ng · galaxy-ngEPSS 0.89%via GHSA
CVE-2026-49402High· 8.1
3mo ago

Deno: Command Injection via spawnSync & spawn on Windows

Deno: Command Injection via spawnSync & spawn on Windows

▾ Twilightdeno · denoEPSS 0.45%via GHSA
GHSA-69qj-pvh9-c5wgHigh· 7.5
3mo ago

yt-dlp: Arbitrary command injection possible if --exec option used with yt-dlp

yt-dlp: Arbitrary command injection possible if --exec option used with yt-dlp

▾ Twilightyt-dlp · yt-dlpvia GHSA
CVE-2026-9863High· 7.5
3mo ago

Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations

Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching…

▾ Twilightfortra · core_privileged_access_manager_serverEPSS 1.0%via NVD
CVE-2026-9862Critical· 9.8
3mo ago

Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service

Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the …

▾ Midnightfortra · core_privileged_access_manager_serverEPSS 1.5%via NVD
CWE-78 vulnerabilities (CVEs) — page 18 · VulnSea