CWE-917Base2 in KEV

Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')

Incomplete in the CWE catalog · 46 CVEs mapped

46
CVEs mapped
2
In KEV
8.6
Median CVSS
What it is

The product constructs all or part of an expression language (EL) statement in a framework such as a Java Server Page (JSP) using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended EL statement before it is executed.

Recent examples
8.9cvss
CVE-2026-65591

n8n before 1.123.64 Sanitizer Bypass Remote Code Execution

n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. An authenticated user with workflow create or modify permissions can craft a malicious expression to bypass the sanitizer and achieve host-level code execution as the n8n process. The legacy expression engine is the default in affected versions. Fixed in n8n 1.123.64, 2.29.8, and 2.30.1.

HIGHno explanation yet
0%
epss
7.5cvss
CVE-2026-57281

CVE-2026-57281 - HIGH Severity Vulnerability

Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying an extensions member, allowing attackers able to run sandboxed Groovy scripts to execute code outside the sandbox if a suitable script is present on the classpath of the component that evaluates the script.

HIGHno explanation yet
1%
epss
9.8cvss
CVE-2026-11561

SSTI in Soagen Informatics' Apinizer

Improper neutralization of special elements used in an expression language statement ('expression language injection') vulnerability in Soagen Informatics Technologies Software and Consulting Inc. Apinizer allows Code Injection. This issue affects Apinizer: from 2026.04.0 before 2026.04.6.

CRITICALno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-917
Abstraction
Base
Structure
Simple
Status
Incomplete
References (4)