CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
What is CWE-77?
CyStack AI
The product constructs all or part of a command using externally influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CyStack analysis based on the official MITRE CWE source 4.20 (04/30/2026).
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Many protocols and products have their own custom command language. While OS or shell command strings are frequently discovered and targeted, developers may not realize that these other command languages might also be vulnerable to attacks.
Detailed description
Many protocols and products have their own custom command language. While OS or shell command strings are frequently discovered and targeted, developers may not realize that these other command languages might also be vulnerable to attacks.
Characteristics
Abstraction: Class. Structure: Simple. Likelihood of exploit: High. Phases of introduction: During Implementation, Realization: vulnerability arises when untrusted data is part of a string executed as a command. Terminology: Command injection; related weakness characteristics include OS command execution and data flow from sources to sinks. Platforms: Not language-specific; AI/ML technologies are listed as applicable technology. Related weaknesses: CWE-74 (Command Injection family) as primary relationships.
Command injection: an attack-oriented phrase for this weakness. Note: often used when "OS command injection" (CWE-78) was intended.
Modes of introduction
Implementation: Command injection vulnerabilities typically occur when:
1. Data enters the application from an untrusted source.
1. The data is part of a string that is executed as a command by the application.
Implementation: REALIZATION: This weakness is caused during implementation of an architectural security tactic.
Common consequences
Scopes and impacts include Integrity, Confidentiality, and Availability. Potential impact is the execution of unauthorized code or commands if an attacker injects a delimiter that ends one command and starts another, enabling new, unintended commands.
Integrity, Confidentiality, Availability
Execute Unauthorized Code or Commands
If a malicious user injects a character (such as a semi-colon) that delimits the end of one command and the beginning of another, it may be possible to then insert an entirely new and unrelated command that was not intended to be executed. This gives an attacker a privilege or capability that they would not otherwise have.
Mitigations
Architecture and Design: If possible, use library calls rather than external processes to recreate functionality. Implementation: Ensure external commands are statically created. Implementation via Input Validation: Treat all input as malicious; use an accept known good strategy and reject or transform inputs not conforming to specifications. Consider properties such as length, type, value ranges, syntax, and business rules. Do not rely solely on blacklist approaches. Operation: enforce run time policy to allow only sanctioned commands. System Configuration: assign permissions to prevent access to privileged files.
Architecture and DesignIf at all possible, use library calls rather than external processes to recreate the desired functionality.
ImplementationIf possible, ensure that all external commands called from the program are statically created.
Implementation · Input ValidationAssume all input is malicious. Use an "accept known good" input validation strategy, i.e., use a list of acceptable inputs that strictly conform to specifications. Reject any input that does not strictly conform to specifications, or transform it into something that does.
When performing input validation, consider all potentially relevant properties, including length, type of input, the full range of acceptable values, missing or extra inputs, syntax, consistency across related fields, and conformance to business rules. As an example of business rule logic, "boat" may be syntactically valid because it only contains alphanumeric characters, but it is not valid if the input is only expected to contain colors such as "red" or "blue."
Do not rely exclusively on looking for malicious or malformed inputs. This is likely to miss at least one undesirable input, especially if the code's environment changes. This can give attackers enough room to bypass the intended validation. However, denylists can be useful for detecting potential attacks or determining which inputs are so malformed that they should be rejected outright.
OperationRun time: Run time policy enforcement may be used in an allowlist fashion to prevent use of any non-sanctioned commands.
System ConfigurationAssign permissions that prevent the user from accessing/opening privileged files.
Detection methods
Automated Static Analysis: Static Application Security Testing (SAST) can identify some instances by analyzing source or binary code for data flow from sources to sinks that may connect to external components.
Automated Static AnalysisAutomated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)Effectiveness: High
Representative vulnerabilities
Representative examples include: CVE-2022-1509 (injection of sed script syntax, sed injection), CVE-2024-5184 (AI model API allowing prompt injection), CVE-2020-11698 (SNMP command injection via configuration), CVE-2019-12921 (image program allowing commands in MVG language), CVE-2022-36069 (gen tool with dash-delimited optional arguments), CVE-1999-0067 (classic OS command injection via unneutralized metacharacter), CVE-2020-9054 (username input leading to OS command injection), CVE-2021-41282, CVE-2019-13398 (sed injection).
These examples illustrate this CWE entry and are not an exhaustive list of related vulnerabilities.
CVE-2022-1509injection of sed script syntax ("sed injection")
CVE-2024-5184API service using a large generative AI model allows direct prompt injection to leak hard-coded system prompts or execute other prompts.
CVE-2020-11698anti-spam product allows injection of SNMP commands into confiuration file
CVE-2019-12921image program allows injection of commands in "Magick Vector Graphics (MVG)" language.
CVE-2022-36069Python-based dependency management tool avoids OS command injection when generating Git commands but allows injection of optional arguments with input beginning with a dash (CWE-88), potentially allowing for code execution.
CVE-1999-0067Canonical example of OS command injection. CGI program does not neutralize "|" metacharacter when invoking a phonebook program.
CVE-2020-9054Chain: improper input validation (CWE-20) in username parameter, leading to OS command injection (CWE-78), as exploited in the wild per CISA KEV.
CVE-2021-41282injection of sed script syntax ("sed injection")
CVE-2019-13398injection of sed script syntax ("sed injection")