command-injection
Safeguard articles tagged "command-injection" — guides, analysis, and best practices for software supply chain and application security.
29 articles
Execa on npm: A Security Review and Safe Usage Guide
Execa is one of the most popular ways to run child processes in Node.js. Here is how to use the execa npm package without opening a command-injection hole.
Zyxel Router Command Injection: CVE-2024-40891 Exploited in the Wild
Threat actors began mass-exploiting a Telnet-based command injection flaw in Zyxel CPE routers, with over 1,500 devices compromised in botnet campaigns. Zyxel initially refused to patch.
Palo Alto Expedition CVE-2024-9463: Command Injection in Migration Tool
Critical command injection vulnerabilities in Palo Alto Networks Expedition tool exposed firewall credentials and configurations, with CISA confirming active exploitation in November 2024.
Modern Command Injection Prevention: Beyond the Basics
Command injection remains in the OWASP Top 10 because developers keep making the same mistakes with new tools. Here is a modern prevention guide covering containers, serverless, and CI/CD.
Zyxel Firewall CVE-2022-30525: Unauthenticated Command Injection in Your Perimeter Defense
CVE-2022-30525 gave attackers unauthenticated OS command injection on Zyxel firewalls. The irony of a firewall being the weakest point in your network security.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.