Eval Injection (CWE-95)
CWE-95 is a Variant of code injection for dynamic evaluation calls such as eval. The product receives input and does not neutralize code syntax before passing it to the evaluator. Even input without special characters may be dangerous if it can reference a function.
About CWE-95
Injected code may read restricted files or data, bypass authentication logic, reach otherwise protected resources and run arbitrary code. Actions taken this way are often not logged.
Mitigations
- +Refactor the code so that eval or equivalent dynamic evaluation is not needed.
- +Validate input against a strict allowlist of acceptable values.
- +Decode and canonicalize input before validating it, and avoid decoding twice.
- +Do not treat safer parsing helpers as a fix for untrusted data; the Python documentation discourages ast.literal_eval() on untrusted input.
Detection
Automated static analysis (SAST) is rated highly effective for tracing input into evaluation calls.
CWE-95 Vulnerabilities
8 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-33017 | Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint | langflow-ai | 9.3 | 24.8% | KEV | 2026-03-20 |
| CVE-2025-24893 | Remote code execution as guest via SolrSearchMacros request in xwiki | xwiki | 9.8 | 99.9% | KEV | 2025-02-20 |
| CVE-2024-36401 | Remote Code Execution (RCE) vulnerability in evaluating property name expressions in Geoserver | geoserver | 9.8 | 99.8% | KEV | 2024-07-01 |
| CVE-2023-7101 | Arbitrary Code Execution (ACE) Vulnerability | Douglas Wilson | 7.8 | 19.1% | KEV | 2023-12-24 |
| CVE-2026-0769 | Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability | Langflow | 9.8 | 32.3% | 2026-01-23 | |
| CVE-2026-1470 | Authenticated users can bypass the Expression sandbox mechanism to achieve full remote code execution on n8n’s main node. | - | 9.9 | 20.7% | 2026-01-27 | |
| CVE-2026-22666 | Dolibarr ERP/CRM < 23.0.2 Authenticated RCE via dol_eval_standard() | Dolibarr | 8.6 | 15.5% | 2026-04-07 | |
| CVE-2026-61511 | vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php | vBulletin | 9.8 | 5.6% | 2026-07-27 |
Related Weaknesses
Tool Categories That Address This Weakness
Frequently Asked Questions
What is CWE-95?→
CWE-95 is eval injection: input reaches a dynamic evaluation function without neutralization of code syntax.
How does CWE-95 relate to CWE-94?→
CWE-95 is a Variant under code injection that focuses on dynamic evaluation calls. CWE-94 is the broader Base entry.
How many exploited vulnerabilities are classified as CWE-95?→
This database lists 8 CVE records mapped to CWE-95 by their CVE Numbering Authority. 4 of them are in the CISA Known Exploited Vulnerabilities catalog. Examples include CVE-2026-33017, CVE-2025-24893, CVE-2024-36401.
Sources
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.