Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-77'

View all threats tagged with 'cwe-77'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-77

Threats Tagged 'cwe-77'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-8037: CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') in Progress Software LoadMasterCVE-2026-8037
0

CVE-2026-8037 is a critical OS command injection vulnerability in the API of Progress ADC LoadMaster products. It allows an unauthenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints. The vulnerability has a high CVSS score of 9.6, indicating severe impact on confidentiality, integrity, and availability. No affected versions or patch information are currently provided.

Join the discussion
CVE-2026-19243: OS Command Injection in HKUDS nanobotCVE-2026-19243
0

A security vulnerability (CVE-2026-19243) exists in HKUDS nanobot versions up to 0.2.1 in the Shell Allowlist Handler component. The flaw allows remote OS command injection via improper validation of shell commands in the ExecTool._guard_command and ExecTool._spawn functions. The issue is addressed by upgrading to version 0.3.0, which validates each executable shell segment against a configured allowlist. The vulnerability has a CVSS score of 6.3 (medium severity).

Join the discussion
CVE-2026-19268: Command Injection in abdullah1854 MCPGatewayCVE-2026-19268
0

A command injection vulnerability exists in the getUsageByDateRange function of the src/services/claude-usage.ts file in abdullah1854 MCPGateway up to commit 549f494a9e363f40530149de324b8097de424230. The vulnerability allows remote attackers to manipulate the 'since' argument to execute arbitrary commands. The project uses continuous delivery with rolling releases, so no specific affected versions or patches are currently identified. The vulnerability has a CVSS score of 6.3, indicating a medium severity impact, but the database rates it as low severity. No official fix or patch information is available, and the project has not responded to the issue report. Exploit code is publicly available, but no known exploitation in the wild has been reported.

Join the discussion
CVE-2026-19263: Command Injection in INQUIRELAB mcp-bridge-apiCVE-2026-19263
0

A command injection vulnerability exists in the INQUIRELAB mcp-bridge-api component, specifically in an unknown function within the mcp-bridge.js file related to the Servers Endpoint. This vulnerability allows remote attackers to manipulate command or argument inputs to execute arbitrary commands. The product uses a rolling release model, so no specific affected or fixed versions are available yet. A fix has been developed but is pending acceptance via a pull request.

Join the discussion
CVE-2026-19266: Command Injection in Kirachon context-engineCVE-2026-19266
0

A command injection vulnerability exists in Kirachon context-engine up to version 1.9.0 in the execGitCommand function of the src/mcp/utils/gitUtils.ts file. Manipulating the argument 'args' can lead to command injection. Upgrading to version 1.9.1 mitigates this issue.

Join the discussion
CVE-2026-19279: Command Injection in MIMICLab mcp-pdf-visionCVE-2026-19279
0

A command injection vulnerability exists in MIMICLab mcp-pdf-vision version 1.1.0 within the load_pdf function in src/index.ts. The vulnerability arises from unsafe manipulation of the pdfPath/sessionId argument. Exploitation requires local access to the environment. No patch or vendor response has been reported yet. The CVSS score is 5.3, indicating a low severity level.

Join the discussion
CVE-2026-18980: Command Injection in nearai ironclawCVE-2026-18980
0

A command injection vulnerability exists in nearai ironclaw up to version 0.29.1 in the function classify_command_risk within src/tools/builtin/shell.rs. This vulnerability allows remote attackers with limited privileges to execute arbitrary commands. A patch identified by commit a1d7c3ba428ed575900469b207fb5668725f9a71 is available to address this issue. The vulnerability has a CVSS 3.1 score of 6.3, indicating a medium severity level.

Join the discussion
CVE-2026-19022: Command Injection in OpenHandsCVE-2026-19022
0

A command injection vulnerability exists in OpenHands up to version 0.62.0 in the function initialize_repo within the file OpenHands/resolver/send_pull_request.py. This vulnerability allows remote attackers with limited privileges to execute arbitrary commands. The vulnerable code path was removed in version 1.7.0. No official patch or fix advisory is provided, but upgrading to version 1.7.0 or later appears to mitigate the issue.

Join the discussion
CVE-2026-19034: OS Command Injection in Shibby TomatoCVE-2026-19034
0

Shibby Tomato 1.28.0000 contains a high severity vulnerability in the new_qoslimit_stop function within /tmp/qoslimittc_stop.sh. This vulnerability allows remote attackers with high privileges to perform OS command injection via manipulation of the wan_iface argument. The vulnerability is publicly disclosed and may be exploited. The project has been superseded by FreshTomato.

Join the discussion
CVE-2026-19035: OS Command Injection in Shibby TomatoCVE-2026-19035
0

A command injection vulnerability exists in Shibby Tomato 1.28.0000 within the new_qoslimit_start function of /etc/qoslimit. This flaw allows remote attackers with high privileges to execute arbitrary OS commands by manipulating the new_qoslimit_enable argument. The vulnerability has a high severity score of 7.2 and public exploit code is available. The project has been superseded by FreshTomato.

Join the discussion

Showing 1 to 10 of 29 results

Filters:Tag: cwe-77
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses