CWE-95: Eval Injection
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call (e.g. "eval").
178 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-24893 — Remote code execution as guest via SolrSearchMacros request in xwiki
- CVE-2024-36401 — Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
- CVE-2026-33017 — Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
- CVE-2025-68271 — Unauthenticated Remote Code Execution in openc3-api
- CVE-2025-55728 — XWiki Remote Macros vulnerable to remote code execution using the panel macro
- CVE-2025-54322 — Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid paramete
- CVE-2025-49013 — WilderForge vulnerable to code Injection via GitHub Actions Workflows
- CVE-2024-37901 — XWiki Platform vulnerable to remote code execution from account via SearchSuggestConfigSheet
- CVE-2026-1470 — Authenticated users can bypass the Expression sandbox mechanism to achieve full remote code execution on n8n’s main node.
- CVE-2025-50187 — Chamilo: Evaluation of untrusted user input leads to Remote Code Execution
- CVE-2026-0769 — Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability
- CVE-2024-43404 — Remote Code Execution Vulnerability in MEGABOT
- CVE-2024-36404 — GeoTools Remote Code Execution (RCE) vulnerability in evaluating XPath expressions
- CVE-2026-27493 — n8n has Unauthenticated Expression Evaluation via Form Node
- CVE-2025-12140 — RCE in Wirtualna Uczelnia
- CVE-2025-0868 — Remote Code Execution in DocsGPT
- CVE-2026-28370 — In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage
- CVE-2025-27603 — XWiki Confluence Migrator Pro allows Remote Code Execution via unescaped translations
- CVE-2025-55727 — XWiki Remote Macros vulnerable to remote code execution from width parameter in the column macro
- CVE-2025-66474 — XWiki vulnerable to remote code execution through insufficient protection against {{/html}} injection
Recently published
- CVE-2026-80351 — Apache Camel K: Camel K Tenant repositories reach Maven execution inside operator pod
- CVE-2026-78550 — Improper Input Handling in Okta Access Gateway Management Console Exception Handler
- CVE-2026-48273 — ColdFusion | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95)
- CVE-2026-76190 — ColdFusion | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95)
- CVE-2026-79678 — Freeipa: idm: freeipa: idp-add eval() reachable before authorization check allows environment disclosure and denial of service
- CVE-2026-85165 — n8n before 2.36.2 Expression Sandbox Bypass via SpreadElement
- CVE-2026-65643 — Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.
- CVE-2026-19295 — Langflow is affected by multiple remote code execution vulnerabilities due to insufficient code-execution policy enforcement
- CVE-2026-54569 — SENAITE.CORE: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') and Missing Authorization in senaite.core
- CVE-2026-75062 — Eval Injection in google/langfun via default lf.query protocol
- CVE-2026-78136 — chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in _clean_tmode in drivers/ken
- CVE-2026-61539 — Xinference: Remote code execution via unsafe `eval()` in Llama3 tool-call parsing
- CVE-2026-77810 — Code Injection via Gremlin Query Passthrough in Amazon Athena Neptune Connector
- CVE-2026-76833 — @cgauge/yaml npm Package Arbitrary Code Execution via eval() YAML Tag
- CVE-2026-71867 — Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generator
- CVE-2026-71865 — Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli
- CVE-2026-71864 — Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod client
- CVE-2026-71866 — Orval: Import-time RCE via schema property name -> computed-property-key injection in the zod client
- CVE-2026-34398 — FreeCAD: Arbitrary Code Execution via eval() on untrusted project file metadata in BIM Workbench
- CVE-2026-34399 — FreeCAD: Arbitrary Code Execution via eval() on untrusted SVG template scale field in BIM TechDraw Page