CVE-2026-41500: Command Injection Exec Unsanitized Json
Data from JSON.parse() or an async/network response flows into exec() without sanitization. exec() passes its first argument to a shell interpreter (/bin/sh on Unix), so unsanitized remote values containing shell metacharacters (;, &&, $(), backticks) enable arbitrary command execution with the privileges of the calling process. Fix by switching to execFile(
greprules fetch cve-2026-41500-command-injection-exec-unsanitized-json --engine opengrepDescription
Data from JSON.parse() or an async/network response flows into exec() without sanitization. exec() passes its first argument to a shell interpreter (/bin/sh on Unix), so unsanitized remote values containing shell metacharacters (;, &&, $(), backticks) enable arbitrary command execution with the privileges of the calling process. Fix by switching to execFile(
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.