CWE-150: Improper Neutralization of Escape, Meta, or Control Sequences
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as escape, meta, or control character sequences when they are sent to a downstream component.
75 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-25286 — Crayfish allows Remote Code Execution via Homarus Authorization header
- CVE-2025-47284 — Gardener vulnerable to metadata injection for a project secret that can lead to privilege escalation
- CVE-2024-32986 — Arbitrary code execution due to improper sanitization of web app properties in PWAsForFirefox
- CVE-2025-0975 — IBM MQ code execution
- CVE-2024-27936 — Deno interactive permission prompt spoofing via improper ANSI stripping
- CVE-2026-11362 — DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags
- CVE-2026-62948 — OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN hostname → stored XSS in the LuCI admin UI
- CVE-2026-3108 — Terminal Escape Injection in mmctl Report Posts Command
- CVE-2025-15311 — Tanium addressed an unauthorized code execution vulnerability in Tanium Appliance.
- CVE-2026-73414 — Shescape: Shell injection via unescaped parentheses on Windows with CMD
- CVE-2026-50638 — Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections
- CVE-2026-9270 — DataDog::DogStatsd versions through 0.07 for Perl allow metric injections
- CVE-2026-11373 — Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections
- CVE-2026-19591 — OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell
- CVE-2026-45038 — Tabby: Dragging and Dropping a File into Tabby Can Lead to Code Execution
- CVE-2026-25996 — Inspektor Gadget uses unsanitized ANSI Escape Sequences In `columns` Output Mode
- CVE-2026-46720 — Net::Statsd::Tiny versions before 0.3.8 for Perl allowed metric injections
- CVE-2026-50637 — Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injections
- CVE-2025-1692 — MongoDB Shell may be susceptible to control character injection via pasting
- CVE-2026-49147 — App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output modes
Recently published
- CVE-2026-82710 — Terminal escape sequence injection in mix usage_rules.search_docs via package documentation metadata
- CVE-2026-82584 — Terminal escape sequence injection in the mix igniter.install confirmation prompt via package metadata
- CVE-2026-19591 — OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell
- CVE-2026-72847 — broot Terminal Escape Sequence Injection via Unsanitized File and Directory Names in the Tree View
- CVE-2026-75483 — powerlevel10k Control Character Injection via package.json Version
- CVE-2026-73506 — Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data
- CVE-2026-73414 — Shescape: Shell injection via unescaped parentheses on Windows with CMD
- CVE-2026-73036 — Bash-it barbuk Theme 3.2.0 Terminal Escape Sequence Injection via pyproject.toml
- CVE-2026-72913 — Kitty: Command injection into the child shell via chained @kitty-echo + @kitty-ssh DCS escape sequences
- CVE-2026-73035 — npm-check-updates 23.0.2 Terminal Injection via Unsanitized Escape Sequences
- CVE-2026-64654 — GitHub CLI: Terminal escape sequence injection in multiple `gh` commands
- CVE-2026-39879 — SQL injection in syslog-ng SQL destionation driver
- CVE-2026-62948 — OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN hostname → stored XSS in the LuCI admin UI
- CVE-2026-49147 — App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output modes
- CVE-2026-11373 — Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections
- CVE-2026-54057 — Kitty vulnerable to command injection via unsanitized OSC 21 query reply
- CVE-2026-50639 — Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injections
- CVE-2026-50638 — Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections
- CVE-2026-50637 — Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injections
- CVE-2026-11362 — DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags