Robuta

https://advisories.gitlab.com/pypi/tkeasygui/CVE-2025-55037/ TkEasyGUI Vulnerable to OS Command Injection | GitLab Advisory Database (GLAD) CVE-2025-55037 TkEasyGUI Vulnerable to OS Command Injection: Improper neutralization of special elements used in an OS command ('OS Command Injection') issue... os command injectionvulnerablegitlabadvisorydatabase https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-cimc-cmd-inj-mUx4c5AJ.html Cisco Integrated Management Controller CLI Command Injection Vulnerability - Cisco A vulnerability in the CLI of the Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to perform command injection... integrated managementcommand injectionciscocontrollercli https://advisories.gitlab.com/pypi/apache-airflow/CVE-2023-22884/ Command Injection in Apache Airflow and Apache Airflow MySQL Provider | GitLab Advisory Database... CVE-2023-22884 Command Injection in Apache Airflow and Apache Airflow MySQL Provider: Improper Neutralization of Special Elements used in a Command ('Command... command injectionapache airflow https://advisories.gitlab.com/npm/nodemailer/GHSA-c7w3-x93f-qmm8/ Nodemailer has SMTP command injection due to unsanitized `envelope.size` parameter | GitLab... GHSA-c7w3-x93f-qmm8 Nodemailer has SMTP command injection due to unsanitized `envelope.size` parameter: When a custom envelope object is passed to sendMail()... command injectiondue to https://advisories.gitlab.com/npm/gry/CVE-2020-36650/ Improper Neutralization of Special Elements used in a Command ('Command Injection') | GitLab... CVE-2020-36650 Improper Neutralization of Special Elements used in a Command ('Command Injection'): A vulnerability, which was classified as critical, was... special elementscommand injectionimproperneutralization https://www.techtarget.com/searchsecurity/answer/How-does-a-Netgear-vulnerability-enable-command-injection-attacks How does a Netgear vulnerability enable command injection attacks? | TechTarget A security researcher showed how a Netgear vulnerability exposed routers to command injection attacks. Find out how to patch the flaw and stop the attacks. how doescommand injectionnetgearvulnerabilityenable https://community.atlassian.com/forums/Sourcetree-questions/Regarding-the-command-injection-issue/qaq-p/595643 Regarding the command injection issue. Jun 10, 2017 - Greating, I am new to sourcetree, I was checking it before installing it and I read about the command injection issue. I've also checked the questio the commandregardinginjectionissue https://advisories.gitlab.com/npm/simple-git/CVE-2022-25912/ Improper Neutralization of Special Elements used in a Command ('Command Injection') | GitLab... CVE-2022-25912 Improper Neutralization of Special Elements used in a Command ('Command Injection'): The package simple-git before 3.15.0 is vulnerable to... special elementscommand injectionimproperneutralization https://advisories.gitlab.com/npm/lifion-verify-deps/CVE-2021-34078/ OS Command Injection in lifion-verify-deps | GitLab Advisory Database (GLAD) CVE-2021-34078 OS Command Injection in lifion-verify-deps: lifion-verify-dependencies through 1.1.0 is vulnerable to OS command injection via a crafted... os command injection https://advisories.gitlab.com/maven/com.xuxueli/xxl-job/CVE-2022-40929/ Improper Neutralization of Special Elements used in a Command ('Command Injection') | GitLab... CVE-2022-40929 Improper Neutralization of Special Elements used in a Command ('Command Injection'): XXL-JOB 2.2.0 has a Command execution vulnerability in... special elementscommand injectionimproperneutralization https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190306-nxos-NXAPI-cmdinj Cisco NX-OS Software NX-API Command Injection Vulnerability A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges.... command injectioncisconxossoftware https://advisories.gitlab.com/npm/pullit/CVE-2018-25083/ pullit Command Injection vulnerability | GitLab Advisory Database (GLAD) CVE-2018-25083 pullit Command Injection vulnerability: The pullit package before 1.4.0 for Node.js allows OS Command Injection because eval is used on an... command injectionvulnerabilitygitlabadvisorydatabase https://aws.amazon.com/security/security-bulletins/2026-001-AWS/ CVE-2026-0830 - Command Injection in Kiro GitLab Merge Request Helper command injectionmerge requestcve https://advisories.gitlab.com/npm/keep-module-latest/CVE-2023-26128/ keep-module-latest vulnerable to Command Injection due to missing input sanitization | GitLab... CVE-2023-26128 keep-module-latest vulnerable to Command Injection due to missing input sanitization : All versions of the package keep-module-latest are... command injection https://advisories.gitlab.com/maven/de.codecentric/spring-boot-admin-server/CVE-2023-38286/ Improper Neutralization of Special Elements used in a Command ('Command Injection') | GitLab... CVE-2023-38286 Improper Neutralization of Special Elements used in a Command ('Command Injection'): Thymeleaf through 3.1.1.RELEASE, as used in... special elementscommand injectionimproperneutralization https://advisories.gitlab.com/pypi/apache-airflow-providers-mysql/CVE-2023-22884/ Command Injection in Apache Airflow and Apache Airflow MySQL Provider | GitLab Advisory Database... CVE-2023-22884 Command Injection in Apache Airflow and Apache Airflow MySQL Provider: Improper Neutralization of Special Elements used in a Command ('Command... command injectionapache airflow https://advisories.gitlab.com/golang/gogs.io/gogs/GMS-2022-1782/ OS Command Injection in gogs | GitLab Advisory Database (GLAD) GMS-2022-1782 OS Command Injection in gogs: Impact The malicious user is able to upload a crafted config file into repository's .git directory with to gain SSH... os command injectiongogsgitlabadvisorydatabase https://pastebin.com/kpzHKKJu MagpieRSS 0.72 Command injection/code injection and Internal Server side request forgery. -... Pastebin.com is the number one paste tool since 2002. Pastebin is a website where you can store text online for a set period of time. command injection https://advisories.gitlab.com/npm/monorepo-build/CVE-2020-28423/ Improper Neutralization of Special Elements used in a Command ('Command Injection') | GitLab... CVE-2020-28423 Improper Neutralization of Special Elements used in a Command ('Command Injection'): This affects all versions of package monorepo-build. special elementscommand injectionimproperneutralization https://advisories.gitlab.com/npm/basic-ftp/GHSA-chqc-8p9q-pq6q/ basic-ftp has FTP Command Injection via CRLF | GitLab Advisory Database (GLAD) GHSA-chqc-8p9q-pq6q basic-ftp has FTP Command Injection via CRLF: basic-ftp version 5.2.0 allows FTP command injection via CRLF sequences (\r\n) in file path... command injectionbasicftp https://advisories.gitlab.com/pypi/ray/CVE-2023-6019/ Ray OS Command Injection vulnerability | GitLab Advisory Database (GLAD) CVE-2023-6019 Ray OS Command Injection vulnerability: A command injection exists in Ray's cpu_profile URL parameter allowing attackers to execute os commands... os command injectionrayvulnerabilitygitlabadvisory https://advisories.gitlab.com/npm/curljs/CVE-2020-28425/ Improper Neutralization of Special Elements used in a Command ('Command Injection') | GitLab... CVE-2020-28425 Improper Neutralization of Special Elements used in a Command ('Command Injection'): This affects all versions of package curljs. special elementscommand injectionimproperneutralization https://advisories.gitlab.com/composer/magento/project-community-edition/CVE-2020-9576/ Magento command injection vulnerability | GitLab Advisory Database (GLAD) CVE-2020-9576 Magento command injection vulnerability: Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and... command injectionmagentovulnerabilitygitlabadvisory https://advisories.gitlab.com/npm/pg-native/CVE-2022-25852/ Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') | GitLab... CVE-2022-25852 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection'): All versions of package pg-native; all versions of package... in acommand injectionimproperneutralizationargument https://hackaday.com/tag/command-injection/ Command Injection | Hackaday command injectionhackaday https://advisories.gitlab.com/npm/snyk-php-plugin/CVE-2024-48963/ OS Command Injection in Snyk php plugin | GitLab Advisory Database (GLAD) CVE-2024-48963 OS Command Injection in Snyk php plugin: The Snyk php plugin is vulnerable to Code Injection when scanning an untrusted PHP project. The... os command injectionphp pluginsnyk https://advisories.gitlab.com/composer/studio-42/elfinder/CVE-2026-41247/ elFinder: Command injection in resize background color parameter when using ImageMagick CLI |... CVE-2026-41247 elFinder: Command injection in resize background color parameter when using ImageMagick CLI: elFinder contains a command injection vulnerability... command injectionbackground color https://advisories.gitlab.com/npm/nemo-appium/CVE-2022-21129/ nemo-appium vulnerable to OS Command Injection | GitLab Advisory Database (GLAD) CVE-2022-21129 nemo-appium vulnerable to OS Command Injection: Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to... os command injectionnemoappiumvulnerable https://advisories.gitlab.com/npm/mcp-maigret/CVE-2026-2130/ mcp-maigret vulnerable to command injection | GitLab Advisory Database (GLAD) CVE-2026-2130 mcp-maigret vulnerable to command injection: A vulnerability was determined in BurtTheCoder mcp-maigret up to 1.0.12. This affects an unknown... command injectionmcpmaigretvulnerablegitlab https://advisories.gitlab.com/npm/electerm/CVE-2026-41501/ electerm has Command Injection via runLinux funtion | GitLab Advisory Database (GLAD) CVE-2026-41501 electerm has Command Injection via runLinux funtion: What kind of vulnerability is it? Who is impacted? Command Injection vulnerabilities in... command injectionelectermvia https://advisories.gitlab.com/pypi/metagpt/CVE-2026-5972/ FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command | GitLab... CVE-2026-5972 FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command: A vulnerability has been found in FoundationAgents... os command injection https://advisories.gitlab.com/pypi/horovod/CVE-2024-10190/ Horovod Vulnerable to Command Injection | GitLab Advisory Database (GLAD) CVE-2024-10190 Horovod Vulnerable to Command Injection: Horovod versions up to and including v0.28.1 are vulnerable to unauthenticated remote code execution.... command injectionvulnerablegitlabadvisorydatabase https://advisories.gitlab.com/npm/files.photo.gallery/CVE-2024-53615/ files.photo.gallery command injection | GitLab Advisory Database (GLAD) CVE-2024-53615 files.photo.gallery command injection: A command injection vulnerability in the video thumbnail rendering component of files.photo.gallery... photo gallerycommand injectionfilesgitlabadvisory https://advisories.gitlab.com/golang/github.com/fluid-cloudnative/fluid/CVE-2023-51699/ Fluid vulnerable to OS Command Injection for Fluid Users with JuicefsRuntime | GitLab Advisory... CVE-2023-51699 Fluid vulnerable to OS Command Injection for Fluid Users with JuicefsRuntime: OS command injection vulnerability within the Fluid project's... os command injection https://www.f5.com/de_de/glossary/command-injection Command Injection | F5 Understand command injection attacks, where malicious system commands are inserted via user-supplied inputs to compromise web applications. Learn prevention... command injection https://unit42.paloaltonetworks.com/cve-2020-4006/?pdf=print&lg=en&_wpnonce=204c4b3d7c Threat Brief: VMware Command Injection Vulnerability (CVE-2020-4006) Jun 6, 2024 - We share information about CVE-2020-4006 and recommendations for how to mitigate. threat briefcommand injectionvmwarevulnerabilitycve https://advisories.gitlab.com/golang/github.com/neuvector/neuvector/CVE-2025-54469/ NeuVector Enforcer is vulnerable to Command Injection and Buffer overflow | GitLab Advisory... CVE-2025-54469 NeuVector Enforcer is vulnerable to Command Injection and Buffer overflow: A vulnerability was identified in NeuVector, where the enforcer used... command injection https://www.itsc.cuhk.edu.hk/sc/user-trainings/information-security-best-practices/os-command-injection-sql-injection-vulnerabilities-on-palo-alto-expedition-cve-2024-9463-cve-2024-9465/ OS Command Injection & SQL Injection vulnerabilities on Palo Alto Expedition (CVE 2024-9463 &... os command injection https://ccb.belgium.be/advisories/warning-critical-os-command-injection-vulnerability-icewarp-patch-immediately Warning: Critical OS Command Injection vulnerability in IceWarp, Patch Immediately! | CCB Belgium os command injection https://advisories.gitlab.com/maven/org.apache.streampark/streampark/CVE-2023-49898/ Improper Neutralization of Special Elements used in a Command ('Command Injection') | GitLab... CVE-2023-49898 Improper Neutralization of Special Elements used in a Command ('Command Injection'): In streampark, there is a project module that integrates... special elementscommand injectionimproperneutralization https://advisories.gitlab.com/npm/google-it/CVE-2021-34083/ Command injection in google-it | GitLab Advisory Database (GLAD) CVE-2021-34083 Command injection in google-it: Google-it is a Node.js package which allows its users to send search queries to Google and receive the results... command injectiongoogle itgitlabadvisorydatabase https://vuxml.freebsd.org/freebsd/cf75f572-378a-11f1-a119-e36228bfe7d4.html VuXML: python -- more webbrowser.open() command injection vulnerabilities command injectionvuxmlpythonwebbrowseropen https://advisories.gitlab.com/pypi/ms-agent/CVE-2026-2256/ MS-Agent vulnerable to Command Injection | GitLab Advisory Database (GLAD) CVE-2026-2256 MS-Agent vulnerable to Command Injection: A Command Injection vulnerability in ModelScope's MS-Agent versions v1.6.0rc1 and earlier exists,... ms agentcommand injectionvulnerablegitlabadvisory https://advisories.gitlab.com/npm/snyk-go-plugin/CVE-2022-40764/ Improper Neutralization of Special Elements used in a Command ('Command Injection') | GitLab... CVE-2022-40764 Improper Neutralization of Special Elements used in a Command ('Command Injection'): Snyk CLI before 1.996.0 allows arbitrary command execution,... special elementscommand injectionimproperneutralization https://advisories.gitlab.com/pypi/paddlepaddle/CVE-2024-0815/ PaddlePaddle command injection in paddle.utils.download._wget_download | GitLab Advisory Database... CVE-2024-0815 PaddlePaddle command injection in paddle.utils.download._wget_download : Command injection in paddle.utils.download._wget_download (bypass... command injectionpaddlepaddle https://advisories.gitlab.com/golang/github.com/1panel-dev/1panel/CVE-2023-36458/ Improper Neutralization of Special Elements used in a Command ('Command Injection') | GitLab... CVE-2023-36458 Improper Neutralization of Special Elements used in a Command ('Command Injection'): 1Panel is an open source Linux server operation and... special elementscommand injectionimproperneutralization https://advisories.gitlab.com/composer/librenms/librenms/CVE-2022-29712/ Command injection in librenms | GitLab Advisory Database (GLAD) CVE-2022-29712 Command injection in librenms: LibreNMS v22.3.0 was discovered to contain multiple command injection vulnerabilities via the service_ip,... command injectionlibrenmsgitlabadvisorydatabase https://advisories.gitlab.com/composer/studio-42/elfinder/GHSA-8q4h-8crm-5cvc/ elFinder: Command injection in resize background color parameter when using ImageMagick CLI |... GHSA-8q4h-8crm-5cvc elFinder: Command injection in resize background color parameter when using ImageMagick CLI: elFinder contains a command injection... command injectionbackground color https://advisories.gitlab.com/composer/magento/community-edition/CVE-2020-9576/ Magento command injection vulnerability | GitLab Advisory Database (GLAD) CVE-2020-9576 Magento command injection vulnerability: Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and... command injectionmagentovulnerabilitygitlabadvisory https://advisories.gitlab.com/pypi/llama-index-core/CVE-2024-3271/ llama-index-core Command Injection vulnerability | GitLab Advisory Database (GLAD) CVE-2024-3271 llama-index-core Command Injection vulnerability: A command injection vulnerability exists in the run-llama/llama_index repository, specifically... core commandllamaindexinjectionvulnerability https://advisories.gitlab.com/composer/wwbn/avideo/CVE-2026-33648/ AVideo Vulnerable to OS Command Injection via Unsanitized `users_id` and... CVE-2026-33648 AVideo Vulnerable to OS Command Injection via Unsanitized `users_id` and `liveTransmitionHistory_id` in Restreamer Log File Path: The restreamer... os command injectionavideovulnerable https://unit42.paloaltonetworks.com/cve-2020-4006/?pdf=download&lg=en&_wpnonce=99541e2cbe Threat Brief: VMware Command Injection Vulnerability (CVE-2020-4006) Jun 6, 2024 - We share information about CVE-2020-4006 and recommendations for how to mitigate. threat briefcommand injectionvmwarevulnerabilitycve https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-cimc-cmd-inj-3hKN3bVt.html Cisco Integrated Management Controller Command Injection and Remote Code Execution Vulnerabilities... Multiple vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to... remote code executionintegrated managementcommand injectionciscocontroller https://advisories.gitlab.com/pypi/paddlepaddle/CVE-2024-0817/ PaddlePaddle command injection vulnerability | GitLab Advisory Database (GLAD) CVE-2024-0817 PaddlePaddle command injection vulnerability: Command injection in IrGraph.draw in paddlepaddle/paddle 2.6.0 command injectionpaddlepaddlevulnerabilitygitlabadvisory https://advisories.gitlab.com/npm/cycle-import-check/CVE-2022-24377/ cycle-import-check vulnerable to Command Injection | GitLab Advisory Database (GLAD) CVE-2022-24377 cycle-import-check vulnerable to Command Injection: The package cycle-import-check before 1.3.2 is vulnerable to Command Injection via the... command injectioncycleimportcheckvulnerable https://advisories.gitlab.com/pypi/basicsr/CVE-2024-27763/ XPixelGroup BasicSR Command Injection | GitLab Advisory Database (GLAD) CVE-2024-27763 XPixelGroup BasicSR Command Injection: XPixelGroup BasicSR through 1.4.2 might locally allow code execution in contrived situations where... command injectiongitlabadvisorydatabaseglad https://advisories.gitlab.com/npm/@coding-solo/godot-mcp/CVE-2026-25546/ godot-mcp has Command Injection via unsanitized projectPath | GitLab Advisory Database (GLAD) CVE-2026-25546 godot-mcp has Command Injection via unsanitized projectPath: A Command Injection vulnerability in godot-mcp allows remote code execution. The... command injection https://advisories.gitlab.com/composer/baserproject/basercms/CVE-2026-30880/ baserCMS has OS command injection vulnerability in installer | GitLab Advisory Database (GLAD) CVE-2026-30880 baserCMS has OS command injection vulnerability in installer: baserCMS has an OS command injection vulnerability in the installer. os command injection https://advisories.gitlab.com/composer/billz/raspap-webgui/CVE-2022-39987/ Improper Neutralization of Special Elements used in a Command ('Command Injection') | GitLab... CVE-2022-39987 Improper Neutralization of Special Elements used in a Command ('Command Injection'): A Command injection vulnerability in RaspAP 2.8.0 thru... special elementscommand injectionimproperneutralization https://advisories.gitlab.com/pypi/metagpt/CVE-2026-5974/ FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py |... CVE-2026-5974 FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py: A vulnerability was determined in FoundationAgents... os command injection https://unit42.paloaltonetworks.com/cve-2021-32305-websvn/ New Mirai Variant Targets WebSVN Command Injection Vulnerability (CVE-2021-32305) Jun 6, 2024 - We provide analysis of and mitigations for exploits in the wild for a command injection vulnerability, CVE-2021-32305, affecting WebSVN. command injectionnewmiraivarianttargets https://advisories.gitlab.com/npm/interactive-git-checkout/CVE-2025-59046/ interactive-git-checkout has a Command Injection vulnerability | GitLab Advisory Database (GLAD) CVE-2025-59046 interactive-git-checkout has a Command Injection vulnerability: The npm package interactive-git-checkout is an interactive command-line tool... git checkoutcommand injection https://advisories.gitlab.com/npm/@paperclipai/server/GHSA-vr7g-88fq-vhq3/ Paperclip: OS Command Injection via Execution Workspace cleanupCommand | GitLab Advisory Database... GHSA-vr7g-88fq-vhq3 Paperclip: OS Command Injection via Execution Workspace cleanupCommand: A critical OS command injection vulnerability exists in Paperclip's... os command injectionpaperclipvia https://advisories.gitlab.com/npm/adb-mcp/CVE-2025-59834/ Command Injection in adb-mcp MCP Server | GitLab Advisory Database (GLAD) CVE-2025-59834 Command Injection in adb-mcp MCP Server: User initiated and remote command injection on a running MCP Server. command injectionmcp serveradbgitlabadvisory https://advisories.gitlab.com/golang/github.com/icewhaletech/casaos/CVE-2023-37469/ CasaOS Command Injection vulnerability | GitLab Advisory Database (GLAD) CVE-2023-37469 CasaOS Command Injection vulnerability: CasaOS is an open-source personal cloud system. Prior to version 0.4.4, if an authenticated user using... command injectioncasaosvulnerabilitygitlabadvisory https://www.tp-link.com/us/support/faq/5018/ Security Advisory on Authenticated Command Injection Vulnerability on TP-Link TL-WR802N, TL-WR841N... Security Advisory on Authenticated Command Injection Vulnerability on TP-Link TL-WR802N, TL-WR841N and TL-WR840N (CVE-2026-3227) security advisorycommand injection https://advisories.gitlab.com/npm/wifey/CVE-2022-25890/ wifey vulnerable to Command Injection due to improper input sanitization | GitLab Advisory Database... CVE-2022-25890 wifey vulnerable to Command Injection due to improper input sanitization: All versions of the package wifey are vulnerable to Command Injection... command injection https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-injection-sRQnsEU9 Cisco Identity Services Engine Command Injection Vulnerabilities Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform command injection attacks on the underlying... identity services enginecommand injectionciscovulnerabilities https://advisories.gitlab.com/pypi/salt/CVE-2019-17361/ SaltStack Salt is vulnerable to command injection | GitLab Advisory Database (GLAD) CVE-2019-17361 SaltStack Salt is vulnerable to command injection: In SaltStack Salt before 2019.2.3, the salt-api NET API with the ssh client enabled is... command injectionsaltstackvulnerable https://advisories.gitlab.com/composer/magento/community-edition/CVE-2024-20720/ Magento Open Source allows OS Command Injection | GitLab Advisory Database (GLAD) CVE-2024-20720 Magento Open Source allows OS Command Injection: Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper... magento open sourceos command injectionallows https://advisories.gitlab.com/maven/org.apache.kylin/kylin/CVE-2022-43396/ Apache Kylin vulnerable to Command injection by Useless configuration | GitLab Advisory Database... CVE-2022-43396 Apache Kylin vulnerable to Command injection by Useless configuration: In the fix for CVE-2022-24697, a block list is used to filter user input... apache kylincommand injection https://advisories.gitlab.com/npm/is-http2/CVE-2022-25906/ is-http2 vulnerable to Command Injection | GitLab Advisory Database (GLAD) CVE-2022-25906 is-http2 vulnerable to Command Injection: All versions of the package is-http2 is vulnerable to Command Injection due to missing input... command injectionvulnerablegitlabadvisorydatabase https://obscuresecurity.blogspot.com/2012/10/mutiny-command-injection-and-cve-2012.html obscuresec: Mutiny Command Injection and CVE-2012-3001 As with the last post , this post is further explanation of things that I briefly covered at BsidesLV earlier this year. The disclosure pr... command injectionmutinycve https://advisories.gitlab.com/pypi/paddlepaddle/CVE-2023-52310/ PaddlePaddle command injection in get_online_pass_interval | GitLab Advisory Database (GLAD) CVE-2023-52310 PaddlePaddle command injection in get_online_pass_interval: PaddlePaddle before 2.6.0 has a command injection in get_online_pass_interval. This... command injectionget online https://unit42.paloaltonetworks.com/cve-2020-4006/?pdf=print&lg=en&_wpnonce=99541e2cbe Threat Brief: VMware Command Injection Vulnerability (CVE-2020-4006) Jun 6, 2024 - We share information about CVE-2020-4006 and recommendations for how to mitigate. threat briefcommand injectionvmwarevulnerabilitycve https://advisories.gitlab.com/npm/@budibase/server/CVE-2026-25041/ @budibase/server: Command Injection in PostgreSQL Dump Command | GitLab Advisory Database (GLAD) CVE-2026-25041 @budibase/server: Command Injection in PostgreSQL Dump Command: Location: packages/server/src/integrations/postgres.ts:529-531 command injectionbudibaseserver https://unit42.paloaltonetworks.com/cve-2020-4006/?pdf=print&lg=en&_wpnonce=3379b0c290 Threat Brief: VMware Command Injection Vulnerability (CVE-2020-4006) Jun 6, 2024 - We share information about CVE-2020-4006 and recommendations for how to mitigate. threat briefcommand injectionvmwarevulnerabilitycve https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171129-nxos3 Cisco NX-OS System Software CLI Command Injection Vulnerability A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. An attacker would... system softwarecommand injectioncisconxos https://thehackernews.com/2024/09/zyxel-patches-critical-os-command.html Zyxel Patches Critical OS Command Injection Flaw in Access Points and Routers Zyxel releases patches for critical vulnerabilities in routers, including OS command injection flaw CVE-2024-7261. os command injection https://advisories.gitlab.com/npm/@snyk/snyk-hex-plugin/CVE-2022-22984/ Improper Neutralization of Special Elements used in a Command ('Command Injection') | GitLab... CVE-2022-22984 Improper Neutralization of Special Elements used in a Command ('Command Injection'): The package snyk before 1.1064.0; the package... special elementscommand injectionimproperneutralization https://advisories.gitlab.com/maven/org.apache.continuum/continuum/CVE-2016-15057/ Apache Continuum vulnerable to Command Injection through Installations REST API | GitLab Advisory... CVE-2016-15057 Apache Continuum vulnerable to Command Injection through Installations REST API: UNSUPPORTED WHEN ASSIGNED Improper Neutralization of Special... command injection https://advisories.gitlab.com/composer/froxlor/froxlor/CVE-2022-4864/ Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') | GitLab... CVE-2022-4864 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection'): Argument Injection in GitHub repository froxlor/froxlor prior... in acommand injectionimproperneutralizationargument https://advisories.gitlab.com/maven/org.skyscreamer/nevado-jms/CVE-2023-31826/ Command injection in nevado-jms | GitLab Advisory Database (GLAD) CVE-2023-31826 Command injection in nevado-jms: Skyscreamer Open Source Nevado JMS v1.3.2 does not perform security checks when receiving messages. This allows... command injectionnevadojmsgitlabadvisory https://advisories.gitlab.com/pypi/dask/CVE-2024-10096/ Withdrawn Advisory: Dask Vulnerable to Command Injection | GitLab Advisory Database (GLAD) CVE-2024-10096 Withdrawn Advisory: Dask Vulnerable to Command Injection: Withdrawn Advisory This advisory has been withdrawn because it describes intended... command injectionwithdrawnadvisorydaskvulnerable https://advisories.gitlab.com/npm/snowflake-sdk/CVE-2023-34232/ Improper Neutralization of Special Elements used in a Command ('Command Injection') | GitLab... CVE-2023-34232 Improper Neutralization of Special Elements used in a Command ('Command Injection'): snowflake-connector-nodejs, a NodeJS driver for Snowflake,... special elementscommand injectionimproperneutralization https://advisories.gitlab.com/composer/wwbn/avideo/CVE-2023-32073/ Improper Neutralization of Special Elements used in a Command ('Command Injection') | GitLab... CVE-2023-32073 Improper Neutralization of Special Elements used in a Command ('Command Injection'): WWBN AVideo is an open source video platform. In versions... special elementscommand injectionimproperneutralization https://advisories.gitlab.com/npm/@aiondadotcom/mcp-ssh/CVE-2025-9654/ AiondaDotCom mcp-ssh command injection vulnerability in SSH operations | GitLab Advisory Database... CVE-2025-9654 AiondaDotCom mcp-ssh command injection vulnerability in SSH operations: A security flaw has been discovered in AiondaDotCom mcp-ssh up to 1.0.3.... ssh commandmcpinjection https://advisories.gitlab.com/pypi/apache-airflow-providers-odbc/CVE-2023-34395/ Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') | GitLab... CVE-2023-34395 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection'): Improper Neutralization of Argument Delimiters in a Command... in acommand injectionimproperneutralizationargument https://advisories.gitlab.com/composer/billz/raspap-webgui/CVE-2022-39986/ Improper Neutralization of Special Elements used in a Command ('Command Injection') | GitLab... CVE-2022-39986 Improper Neutralization of Special Elements used in a Command ('Command Injection'): A Command injection vulnerability in RaspAP 2.8.0 thru... special elementscommand injectionimproperneutralization https://advisories.gitlab.com/gem/bitcoinrb/GHSA-q66h-m87m-j2q6/ Bitcoinrb Vulnerable to Command injection via RPC | GitLab Advisory Database (GLAD) GHSA-q66h-m87m-j2q6 Bitcoinrb Vulnerable to Command injection via RPC : Unsafe handling of request parameters in the RPC HTTP server results in command... command injectionvulnerable https://advisories.gitlab.com/golang/github.com/hashicorp/go-getter/v2/CVE-2022-26945/ Improper Neutralization of Special Elements used in a Command ('Command Injection') | GitLab... CVE-2022-26945 Improper Neutralization of Special Elements used in a Command ('Command Injection'): go-getter up to 1.5.11 and 2.0.2 allowed protocol... special elementscommand injectionimproperneutralization https://advisories.gitlab.com/npm/font-converter/CVE-2022-21165/ Improper Neutralization of Special Elements used in a Command ('Command Injection') | GitLab... CVE-2022-21165 Improper Neutralization of Special Elements used in a Command ('Command Injection'): All versions of package font-converter is vulnerable to... special elementscommand injectionimproperneutralization https://advisories.gitlab.com/pypi/praisonai/CVE-2026-40088/ PraisonAI Vulnerable to OS Command Injection | GitLab Advisory Database (GLAD) CVE-2026-40088 PraisonAI Vulnerable to OS Command Injection: The execute_command function and workflow shell execution are exposed to user-controlled input via... os command injectionvulnerablegitlabadvisorydatabase https://advisories.gitlab.com/maven/org.apache.kylin/kylin/CVE-2022-44621/ Apache Kylin vulnerable to Command injection by Diagnosis Controller | GitLab Advisory Database... CVE-2022-44621 Apache Kylin vulnerable to Command injection by Diagnosis Controller: Diagnosis Controller miss parameter validation, so user may attacked by... apache kylincommand injection https://advisories.gitlab.com/npm/renovate/GHSA-xv56-3wq5-9997/ Renovate vulnerable to arbitrary command injection via kustomize manager and malicious helm... GHSA-xv56-3wq5-9997 Renovate vulnerable to arbitrary command injection via kustomize manager and malicious helm repository: The user-provided chart name in the... command injection https://advisories.gitlab.com/composer/magento/project-community-edition/CVE-2024-39401/ Magento OS Command ('OS Command Injection') vulnerability | GitLab Advisory Database (GLAD) CVE-2024-39401 Magento OS Command ('OS Command Injection') vulnerability: Magento versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by... os command injectionmagentovulnerabilitygitlabadvisory https://advisories.gitlab.com/maven/org.apache.kylin/kylin/CVE-2022-24697/ Improper Neutralization of Special Elements used in a Command ('Command Injection') | GitLab... CVE-2022-24697 Improper Neutralization of Special Elements used in a Command ('Command Injection'): Kylin's cube designer function has a command injection... special elementscommand injectionimproperneutralization https://support.lenovo.com/pl/pl/solutions/ps500196-legacy-server-bmc-remote-command-injection Legacy Server BMC Remote Command Injection - Lenovo Support PL Legacy Server BMC Remote Command Injection command injectionlenovo supportlegacyserverbmc https://advisories.gitlab.com/golang/github.com/tencent/weknora/CVE-2026-22688/ WeKnora has Command Injection in MCP stdio test | GitLab Advisory Database (GLAD) CVE-2026-22688 WeKnora has Command Injection in MCP stdio test: Remote Code Execution (RCE): Arbitrary command execution enables file creation/modification,... command injection https://advisories.gitlab.com/golang/gogs.io/gogs/CVE-2021-32546/ OS Command Injection in gogs | GitLab Advisory Database (GLAD) CVE-2021-32546 OS Command Injection in gogs: Missing input validation in internal/db/repo_editor.go in Gogs before 0.12.8 allows an attacker to execute code... os command injectiongogsgitlabadvisorydatabase