CWE-149: Improper Neutralization of Quoting Syntax
Quotes injected into a product can be used to compromise a system. As data are parsed, an injected/absent/duplicate/malformed use of quotes may cause the process to take unexpected actions.
Last updated
Overview
CWE-149 (Improper Neutralization of Quoting Syntax) is a variant-level software weakness catalogued by MITRE in the Common Weakness Enumeration (CWE). It describes a recurring type of mistake that can lead to exploitable security vulnerabilities.
Real-world CVEs
5 recorded CVEs are caused by CWE-149 (Improper Neutralization of Quoting Syntax). The highest-severity and most recent are shown first. 1 new CWE-149 CVE has been recorded so far in 2026 (3 in 2025).