Skip to content

security_identifier

CWE-78

CWE-78 is a Common Weakness Enumeration category for OS command injection, where untrusted input reaches a system shell, enabling arbitrary command execution.

Known aliases

  • CWE-78
  • OS Command Injection

Relationships

No evidence-backed relationships are recorded.

Current stories

build1 publisher

Arista names four fixed VCO builds for a command injection already in use

CVE-2026-16812 scores 10.0 on both CVSS scales because the scope metrics say a compromise of the orchestrator host does not stay inside the orchestrator, and on-prem operators are the ones who have to schedule the fix.

Publishers:arista.com

Reality

Evidence62
Adoption35
Hype gap−12
Incentives70
Confidence58
build1 publisher

GOautodial runs an agent's logout parameter through /bin/sh

The goPhone value is escaped for SQL, then dropped into an exec() string that PHP runs through /bin/sh. Any active agent can trigger the logout call, and on a production box the injected command runs under sudo.

Publishers:dev.to

Reality

Evidence60
Adoption28
Hype gap+14
Incentives58
Confidence55