command-injection
Safeguard articles tagged "command-injection" — guides, analysis, and best practices for software supply chain and application security.
35 articles
A Weather Station Gateway With Root-Level Command Injection, No Login Required
Smartbedded Meteobridge's CGI-shell-script web interface lets a remote unauthenticated attacker execute arbitrary commands as root, a legacy embedded architecture problem still live in 2026.
Two More FreePBX CVEs, Six Years Apart, Confirmed Exploited on the Same Day
A 2025 command injection bug in FreePBX's Endpoint Manager and a 2019 authentication bypass landed in KEV together, additional findings beyond FreePBX coverage published elsewhere in this series.
BeyondTrust Remote Support's Pre-Auth Command Injection Is a Ransomware Vector
CVE-2026-1731 lets an unauthenticated attacker run OS commands on BeyondTrust Remote Support and Privileged Remote Access, with CISA confirming active ransomware use.
Metro4Shell: React Native's Development Server Exposed to Anyone on the Network
CVE-2025-11953 lets unauthenticated attackers run arbitrary commands on developer machines through React Native's Metro Development Server, which binds to external interfaces by default.
LiteLLM's AI Gateway Shipped a Critical SQL Injection and a Command Injection in the Same Patch Cycle
An unauthenticated SQL injection in API key checks and an authenticated command injection via MCP preview endpoints both hit BerriAI's LiteLLM proxy, fixed together in v1.83.7.
Lantronix EDS5000's Failed-Login Logging Was Itself the Vulnerability
CVE-2025-67038 triggers on a failed login attempt alone: the device server shells out to write a log entry, concatenating the attacker-supplied username unsanitised into the command.
Three Maximum-Severity UniFi OS CVEs, Same Day, Same Product
Ubiquiti UniFi OS had three CVSS 10.0 vulnerabilities — command injection, path traversal, and access control failure — all confirmed exploited on the same day in June 2026.
FortiSandbox Had Two Command Injection CVEs on the Same Day — the Irony Is the Point
Fortinet FortiSandbox, built to detonate suspicious files safely, had two command injection vulnerabilities confirmed exploited on the same day in July 2026.
CVE-2026-8037: When the Function That Escapes Your Input Is the Bug
Progress Kemp LoadMaster's flaw lives inside escape_quotes(), the routine meant to neutralise dangerous input. It fails to null-terminate, turning a sanitiser into unauthenticated command injection.
Python mailcap insecure shell command construction (CVE-2015-20107)
Python mailcap shell injection (CVE-2015-20107) lets attackers run arbitrary commands via unescaped filenames. Here is how to detect and fix it.
OS command injection explained
OS command injection lets attackers run arbitrary shell commands via unsanitized input. See how it works, real CVEs like PAN-OS 2024, and fixes.
CVE-2023-5752: Command Injection in pip via Mercurial Revisions
Installing a package from a Mercurial URL with a crafted revision let attackers inject hg config options. Here is how CVE-2023-5752 works and how to fix it.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.