CWE-150— Improper Neutralization of Escape, Meta, or Control Sequences
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as escape, meta, or control character sequences when they are sent to a downstream component.— MITRE CWE catalog
89 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-150page 1 of 2
- CVE-2022-30123CRITICALCVSS 10.0EG 10.02022-12-05
A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack.
- CVE-2020-6932CRITICALCVSS 10.0EG 10.02020-08-12
An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platform versions 6.4.0 to 6.6.0 could allow an attacker to potentially read arbitrary files and run arb…
- CVE-2025-47284CRITICALCVSS 9.9EG 9.92025-05-19
Gardener implements the automated management and operation of Kubernetes clusters as a service. A security vulnerability was discovered in the `gardenlet` component of Gardener prior to versions 1.116.4, 1.117.5, 1.118.2, and 1.119.0. It c…
- CVE-2023-26055CRITICALCVSS 9.9EG 9.92023-03-02
XWiki Commons are technical libraries common to several other top level XWiki projects. Starting in version 3.1-milestone-1, any user can edit their own profile and inject code, which is going to be executed with programming right. The sam…
- CVE-2026-11362CRITICALCVSS 9.8EG 9.82026-06-05
DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources. The format_event method (used by t…
- CVE-2026-25996CRITICALCVSS 9.8EG 9.82026-02-12
Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. String fields from eBPF events in columns output mode are rendered to the terminal without any sa…
- CVE-2025-25286CRITICALCVSS 9.8EG 9.82025-02-13
Crayfish is a collection of Islandora 8 microservices, one of which, Homarus, provides FFmpeg as a microservice. Prior to Crayfish version 4.1.0, remote code execution may be possible in web-accessible installations of Homarus in certain c…
- CVE-2023-3265CRITICALCVSS 9.8EG 9.82023-08-14
An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the username, allowing an attacker to login into the application with the default user "cyberpower" by appending a non-printabl…
- CVE-2017-0899CRITICALCVSS 9.8EG 9.82017-08-31
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences.
- CVE-2026-62948CRITICALCVSS 9.6EG 9.62026-07-15
OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/statefiles.c statefiles_write_state6() and statefiles_write_state4(…
- CVE-2025-55754CRITICALCVSS 9.6EG 9.62025-10-27
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console s…
- CVE-2024-32986CRITICALCVSS 9.6EG 9.62024-05-03
PWAsForFirefox is a tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox. Due to improper sanitization of web app properties (such as name, description, shortcuts), web apps were able to inject additional lines in…
- CVE-2026-73414CRITICALCVSS 9.2EG 9.22026-08-12
Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/win/cmd.js does not escape `(` and `)` when applications use the escape or escapeAll APIs on Windows with shell set to c…
- CVE-2026-11373CRITICALCVSS 9.1EG 9.12026-06-22
Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for the statsite protocol, which is a variant of statsd. Newlines are not removed from metric names, allowing metric injecti…
- CVE-2026-50638CRITICALCVSS 9.1EG 9.12026-06-10
Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics, separated by newlines, to be sent per packet. Metric…
- CVE-2026-9270CRITICALCVSS 9.1EG 9.12026-06-05
DataDog::DogStatsd versions through 0.07 for Perl allow metric injections. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources. The send_stats method does not remove newlines fro…
- CVE-2026-26149CRITICALCVSS 9.0EG 9.02026-04-14
Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network.
- CVE-2026-19591HIGHCVSS 8.8EG 8.82026-09-01
OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe because their command-safety parser interpreted PowerShell's stop-parsing token (--%) differently than…
- CVE-2026-3108HIGHCVSS 8.8EG 8.82026-03-26
Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to sanitize user-controlled post content in the mmctl commands terminal output which allows attackers to manipulate administrator terminals …
- CVE-2025-0975HIGHCVSS 8.8EG 8.82025-02-28
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD console could allow an authenticated user to execute code due to improper neutralization of escape characters.
- CVE-2024-52005HIGHCVSS 8.8EG 8.82025-01-15
Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called "sideband channel". These messages will…
- CVE-2024-56201HIGHCVSS 8.8EG 8.82024-12-23
Jinja is an extensible templating engine. In versions on the 3.x branch prior to 3.1.5, a bug in the Jinja compiler allows an attacker that controls both the content and filename of a template to execute arbitrary Python code, regardless o…
- CVE-2024-27936HIGHCVSS 8.8EG 8.82024-03-21
Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. Starting in version 1.32.1 and prior to version 1.41.0 of the deno library, maliciously crafted permission request can show the spoofed permission prompt by in…
- CVE-2023-28446HIGHCVSS 8.8EG 8.82023-03-24
Deno is a simple, modern and secure runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Arbitrary program names without any ANSI filtering allows any malicious program to clear the first 2 lines of a `op_spawn_child` o…
- CVE-2021-25310HIGHCVSS 8.8EG 8.82021-02-02
The administration web interface on Belkin Linksys WRT160NL 1.0.04.002_US_20130619 devices allows remote authenticated attackers to execute system commands with root privileges via shell metacharacters in the ui_language POST parameter to …
- CVE-2026-105801HIGHCVSS 8.4EG 8.42026-10-06
openapi-python-client generates Python clients from OpenAPI documents. Prior to 0.29.1, the generator does not safely neutralize malicious OpenAPI document content before rendering string, docstring, and f-string contexts in generated Pyth…
- CVE-2026-90895HIGHCVSS 8.4EG 8.42026-09-14
Affected versions of MISP’s interactive CLI shell implement access control independently from the normal web application, causing several authorization inconsistencies. The patch shows that CLI access could differ from the web applicat…
- CVE-2026-50637HIGHCVSS 8.2EG 8.22026-06-10
Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions) allow mutiple metrics, separated by newlines, to be sent per packet. The send method does not va…
- CVE-2026-46720HIGHCVSS 8.2EG 8.22026-05-17
Net::Statsd::Tiny versions before 0.3.8 for Perl allowed metric injections. The metric names and set values were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics.
- CVE-2026-104026HIGHCVSS 7.8EG 7.82026-10-02
In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to be embedded in Git subtree URLs. A maliciously constructed repository, if cloned by a target, could trigger code execution on otherwise read-only actions such…
- CVE-2026-54057HIGHCVSS 7.8EG 7.82026-06-12
Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.3, kitty's OSC 21 (color-control) query reply reflects attacker-controlled bytes, including newlines, into the shell's input without sanitization. Version 0.47.3 fixes…
- CVE-2026-45038HIGHCVSS 7.8EG 7.82026-05-15
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, since Tabby does not escape control characters from file paths when dragging and dropping a file into it, code execution can be achieved. This vulnerab…
- CVE-2025-15311HIGHCVSS 7.8EG 7.82026-02-05
Tanium addressed an unauthorized code execution vulnerability in Tanium Appliance.
- CVE-2026-103431HIGHCVSS 7.7EG 7.72026-10-01
colmux in collectl before 4.3.20.2 does not sanitize ANSI/VT100 terminal escape sequences in data received from remote collectl instances before displaying it, allowing a local user on a monitored host to inject escape sequences into the t…
- CVE-2026-49147HIGHCVSS 7.5EG 7.52026-07-08
App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output modes. When ack prints a filename whose basename contains terminal control bytes such as ANSI escape sequences, those b…
- CVE-2026-46741HIGHCVSS 7.5EG 7.52026-06-04
Etsy::StatsD versions through 1.002002 for Perl allow metric injections. The metric names and values are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. Note tha…
- CVE-2024-47252HIGHCVSS 7.5EG 7.52025-07-10
Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations. In a logging configuration where CustomL…
- CVE-2024-52006HIGHCVSS 7.5EG 7.52025-01-14
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. Git defines a line-based protocol that is used to exchange information b…
- CVE-2024-36052HIGHCVSS 7.5EG 7.52024-05-21
RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a different issue than CVE-2024-33899.
- CVE-2026-21521HIGHCVSS 7.4EG 7.42026-01-22
Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose information over a network.
- CVE-2026-72913HIGHCVSS 7.3EG 7.32026-08-10
Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/window.py write unauthenticated data to the child shell's stdin, where handle_remote_echo accepts printable shell command c…
- CVE-2026-8788HIGHCVSS 7.3EG 7.32026-05-18
Net::Statsd::Lite versions through 0.10.0 for Perl allowed metric injections. The values from the set_add method were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metri…
- CVE-2003-0063HIGHCVSS 7.3EG 7.32003-03-03
The xterm terminal emulator in XFree86 4.2.0 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a fil…
- CVE-2026-39879HIGHCVSS 7.1EG 7.12026-07-20
Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 are vulnerable to SQL injection from an un…
- CVE-2024-33899HIGHCVSS 7.1EG 7.12024-04-29
RARLAB WinRAR before 7.00, on Linux and UNIX platforms, allows attackers to spoof the screen output, or cause a denial of service, via ANSI escape sequences.
- CVE-2025-62845MEDIUMCVSS 6.7EG 6.72026-03-20
An improper neutralization of escape, meta, or control sequences vulnerability has been reported to affect QHora. If a local attacker gains an administrator account, they can then exploit the vulnerability to cause unexpected behavior. We…
- CVE-2026-50639MEDIUMCVSS 6.5EG 6.52026-06-10
Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injections. The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics, separated by newlines, to be sent per packet. Metrics…
- CVE-2026-8722MEDIUMCVSS 6.5EG 6.52026-06-03
Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics.
- CVE-2026-46719MEDIUMCVSS 6.5EG 6.52026-05-16
Net::Statsd::Lite versions before 0.9.0 for Perl allowed metric injections. The metric names were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics.
- CVE-2026-41526MEDIUMCVSS 6.5EG 6.52026-04-28
In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing does not adequately handle metacharacters, leading to an escape from the shell. All applica…
Map vulnerabilities like CWE-150 to your infrastructure
EchelonGraph correlates every CVE — across CWE-150 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →