← Learn

Definition

What is command injection?

We scanned nearly 2,000 AI-built apps and 1 in 8 shipped a high-severity flaw. Want to check yours?Scan free →

Command injection is when untrusted input is inserted into a shell command your server runs, letting an attacker append their own commands. Because the shell interprets characters like semicolons and pipes, input such as file.txt; rm -rf / can turn one intended command into several, giving the attacker control of the server.

Why the shell is the danger

Running a command through a shell means the shell parses the whole string, so any special character in the input is interpreted, not treated as data. Building the command by pasting input into a string is what opens the door; the shell does the rest.

The safe pattern

Do not build a shell string from input. Pass the program and its arguments as a list so the input is handed to the program as data, never parsed by a shell. In Node, avoid exec with an interpolated string and use execFile or spawn with an args array; in Python, avoid shell=True and pass a list to subprocess.run.

What this means for AI-generated code

String interpolation into a shell command is the most natural way to write it, and it works perfectly in a demo with clean input. The AI tool has no signal that the input will ever be hostile, so it ships the interpolated version.

Want to know if your app has this issue? Scan a public repo free, no account needed.

Scan a repo →

Related: fix a command injection

What Is Command Injection? How It Works and How to Stop It: Prbl