command-injection
Safeguard articles tagged "command-injection" — guides, analysis, and best practices for software supply chain and application security.
30 articles
CVE-2026-8037: When the Function That Escapes Your Input Is the Bug
Progress Kemp LoadMaster's flaw lives inside escape_quotes(), the routine meant to neutralise dangerous input. It fails to null-terminate, turning a sanitiser into unauthenticated command injection.
Python mailcap insecure shell command construction (CVE-2015-20107)
Python mailcap shell injection (CVE-2015-20107) lets attackers run arbitrary commands via unescaped filenames. Here is how to detect and fix it.
OS command injection explained
OS command injection lets attackers run arbitrary shell commands via unsanitized input. See how it works, real CVEs like PAN-OS 2024, and fixes.
CVE-2023-5752: Command Injection in pip via Mercurial Revisions
Installing a package from a Mercurial URL with a crafted revision let attackers inject hg config options. Here is how CVE-2023-5752 works and how to fix it.
Go's 'go get' Remote Code Execution via Crafted Import Pa...
A deep dive into CVE-2018-16873, the Go 'go get' remote code execution vulnerability caused by crafted import paths and command injection in DVCS fetches.
The glob npm Package and CVE-2025-64756: What Happened and How to Fix It
In November 2025 a command-injection flaw in the glob npm CLI lit up scanners across the Node ecosystem. Here is what CVE-2025-64756 actually affects and how to remediate it.
Git Argument Injection via Crafted SSH URL (CVE-2017-1000...
CVE-2017-1000117 let a malicious repo run code on anyone who cloned it via a crafted ssh:// URL. Impact, affected Git versions, CVSS, and fixes.
Root cause: CVE-2022-40764, the Snyk CLI command injection
A crafted vendor.json field let attackers run shell commands from inside a security scanner — CVE-2022-40764 shows why CLI tools must never build shell strings.
CVE-2023-36414: The Azure Identity SDK RCE You Should Patch
CVE-2023-36414 is a remote code execution flaw in the Azure Identity SDK for .NET. Here is how the injection works and which version closes it.
Securing MCP Servers for AI Agents
Five CVEs in 2025 alone trace MCP tool compromise back to one root cause: unsanitized strings piped into exec(). Here's how to expose and consume MCP safely.
Ghostscript (CVE-2023-36664) Explained: Command Injection via Pipe Devices
CVE-2023-36664 let a crafted PostScript or EPS file run system commands through Ghostscript's mishandling of pipe device filenames. Because Ghostscript hides behind image tools, the blast radius was wide.
Ivanti Connect Secure CVE-2024-21887 Explained: Command Injection in a Two-Bug Chain
CVE-2024-21887 is a command injection in Ivanti Connect Secure that, chained with the auth bypass CVE-2023-46805, gave attackers unauthenticated RCE. Here is the timeline, root cause, and patched versions.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.