CWE-153: Improper Neutralization of Substitution Characters
low-riskThe product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as substitution characters when they are sent to a downstream component.
Abstraction: Variant
Common Consequences
Integrity
→
Unexpected State
Real-World Examples (4)
| CVE | CVSS | EPSS | KEV |
|---|---|---|---|
| CVE-2025-49003 | 9.8 | 0.8% | — |
| CVE-2025-53004 | 9.8 | 0.2% | — |
| CVE-2025-53005 | 9.8 | 0.2% | — |
| CVE-2025-53006 | 9.8 | 0.1% | — |
0
/ 100
low-risk
Active Threat
0/50 · Minimal
Exploit Availability
0/50 · Minimal