CWE-78: Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’)¶
MITRE Corporation. (2025). CWE-78: Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’). Common Weakness Enumeration.
Cited by¶
1 citation across 1 artifact.
Each citation links to the sentence it supports in the citing article.
Mechanisms¶
- Structured Command Construction
- Its strength is that it eliminates the string-concatenation surface injection depends on, and it works for targets that offer no parameter binding at all — shells, paths, HTTP APIs, agent tool calls — which makes it the standard defense against OS command injection.
This sourceIdentifies OS-command injection risk from improperly neutralized command elements and recommends avoiding shell invocation or strictly constraining command construction.
- Its strength is that it eliminates the string-concatenation surface injection depends on, and it works for targets that offer no parameter binding at all — shells, paths, HTTP APIs, agent tool calls — which makes it the standard defense against OS command injection.
Verification¶
Does it exist? Not checked yet. This entry carries no identifier to resolve. It was extracted from the citation as written in the article, normalized, and deduplicated against the rest of the registry.
Does it back the claim? Not recorded. The single citation of this work carries no recorded support check.
Was it audited? Yes. A second, independent pass read the citation against the article text and recorded a verdict.
Support is checked per citation rather than per work — the same source can be cited soundly in one article and wrongly in another. Per-citation recording began recently, so a citation with no recorded check is a gap in the record rather than evidence it went unchecked.
See how references were verified.
Registry ID ref:d9d5bc7a2a3d · see in the full table