Skip to main content

About CWE-95

Injected code may read restricted files or data, bypass authentication logic, reach otherwise protected resources and run arbitrary code. Actions taken this way are often not logged.

MITRE name
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
Abstraction
Variant: linked to a certain type of product, typically a specific language or technology
Status
Incomplete

Mitigations

  • +Refactor the code so that eval or equivalent dynamic evaluation is not needed.
  • +Validate input against a strict allowlist of acceptable values.
  • +Decode and canonicalize input before validating it, and avoid decoding twice.
  • +Do not treat safer parsing helpers as a fix for untrusted data; the Python documentation discourages ast.literal_eval() on untrusted input.

Detection
Automated static analysis (SAST) is rated highly effective for tracing input into evaluation calls.

CWE-95 Vulnerabilities

8 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-33017
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
langflow-ai9.324.8%KEV2026-03-20
CVE-2025-24893
Remote code execution as guest via SolrSearchMacros request in xwiki
xwiki9.899.9%KEV2025-02-20
CVE-2024-36401
Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver
geoserver9.899.8%KEV2024-07-01
CVE-2023-7101
Arbitrary Code Execution (ACE) Vulnerability
Douglas Wilson7.819.1%KEV2023-12-24
CVE-2026-0769
Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability
Langflow9.832.3%2026-01-23
CVE-2026-1470
Authenticated users can bypass the Expression sandbox mechanism to achieve full remote code execution on n8n’s main node.
-9.920.7%2026-01-27
CVE-2026-22666
Dolibarr ERP/CRM < 23.0.2 Authenticated RCE via dol_eval_standard()
Dolibarr8.615.5%2026-04-07
CVE-2026-61511
vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php
vBulletin9.85.6%2026-07-27

Related Weaknesses

Frequently Asked Questions

What is CWE-95?→

CWE-95 is eval injection: input reaches a dynamic evaluation function without neutralization of code syntax.

How does CWE-95 relate to CWE-94?→

CWE-95 is a Variant under code injection that focuses on dynamic evaluation calls. CWE-94 is the broader Base entry.

How many exploited vulnerabilities are classified as CWE-95?→

This database lists 8 CVE records mapped to CWE-95 by their CVE Numbering Authority. 4 of them are in the CISA Known Exploited Vulnerabilities catalog. Examples include CVE-2026-33017, CVE-2025-24893, CVE-2024-36401.

Sources

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.