CWE-78
CVEs classified under CWE-78, newest first.
727 CVEsRSS
CVE-2026-57282Medium· 5.0Jenkins Git client Plugin has an OS command injection vulnerability on agents
Jenkins Git client Plugin has an OS command injection vulnerability on agents
GHSA-jj69-4grx-fqj5Critical· 7.8Duplicate Advisory: Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses
Duplicate Advisory: Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses
CVE-2026-12537High· 7.8⚖ disputedImproper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker …
Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker …
GHSA-v772-658q-978pLowDuplicate Advisory: ImageMagick: SVG-to-MVG Command Injection via coders/svg.c
Duplicate Advisory: ImageMagick: SVG-to-MVG Command Injection via coders/svg.c
CVE-2026-56379High· 8.1ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands
ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector G…
CVE-2026-55173High· 8.1AVideo has an incomplete fix of CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sink
AVideo has an incomplete fix of CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sink
CVE-2026-55441High· 8.6Mise vulnerable to arbitrary command execution via task-include files in an untrusted, config-less repository
Mise vulnerable to arbitrary command execution via task-include files in an untrusted, config-less repository
CVE-2026-55448Medium· 6.3Mise's local credential_command executes untrusted config
Mise's local credential_command executes untrusted config
CVE-2026-46606High· 7.8Glances is Vulnerable to Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vms/engines/virsh.py
Glances is Vulnerable to Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vms/engines/virsh.py
CVE-2026-54051Critical· 9.9Network-AI: Improper Neutralization of Special Elements used in an OS Command
Network-AI: Improper Neutralization of Special Elements used in an OS Command
GHSA-wg5p-8h9p-3mr7High· 8.6agent-coderag: Gradle Wrapper Execution During Dependency Discovery Enables Arbitrary Code Execution
agent-coderag: Gradle Wrapper Execution During Dependency Discovery Enables Arbitrary Code Execution
GHSA-vcv2-r9jh-99m5High· 8.8Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into execSync
Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into execSync
CVE-2026-55849High@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument
@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument
GHSA-c3xh-98xp-6qhfHighgithubtoplanguages: Command Injection via Issue Title in Discord Notification Workflow
githubtoplanguages: Command Injection via Issue Title in Discord Notification Workflow
GHSA-v847-hxxw-3pxgHigh· 7.8PraisonAI recipe.run_stream skips dangerous-tool policy enforcement
PraisonAI recipe.run_stream skips dangerous-tool policy enforcement
GHSA-w6h2-fr4q-xvxvHigh· 8.8PraisonAI: Compute-bridged file tools allow shell command injection
PraisonAI: Compute-bridged file tools allow shell command injection
GHSA-p75f-6fp4-p57wCritical· 9.8PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai
PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai
GHSA-vjv9-7m7j-h833High· 8.8npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining
npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining
GHSA-5jv7-2mjm-h6qjHigh· 8.8npm PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining
npm PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining
GHSA-7qw2-w5rc-37x2High· 7.8PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml
PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml
CVE-2026-53848Low· 4.3OpenClaw: Exec allowlist could miss side effects from transparent command wrappers
OpenClaw: Exec allowlist could miss side effects from transparent command wrappers
CVE-2026-53855High· 8.1OpenClaw: Shell positional parameters could weaken strict inline-eval checks
OpenClaw: Shell positional parameters could weaken strict inline-eval checks
CVE-2026-0755Critical· 9.80daygemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755)
gemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755)
CVE-2026-55743Critical· 9.6The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed to execute arbitrary OS commands with the privileges of the desktop user.
The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed to execute arbitrary OS commands with the privileges of the desktop user.
CVE-2026-55748Medium· 6.0OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters
OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types…
CVE-2026-12398High· 7.5Galaxy NG: command injection vulnerability
Galaxy NG: command injection vulnerability
CVE-2026-49402High· 8.1Deno: Command Injection via spawnSync & spawn on Windows
Deno: Command Injection via spawnSync & spawn on Windows
GHSA-69qj-pvh9-c5wgHigh· 7.5yt-dlp: Arbitrary command injection possible if --exec option used with yt-dlp
yt-dlp: Arbitrary command injection possible if --exec option used with yt-dlp
CVE-2026-9863High· 7.5Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations
Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching…
CVE-2026-9862Critical· 9.8Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service
Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the …