Weaknesses of type CWE-77

2,811 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2024-11013HIGHCommand Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27, for Ver10.9 up to VEPSS 1.1%CVE-2024-36138HIGHBypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via childEPSS 1.1%CVE-2025-58178HIGHCommand Injection via sonarqube-scan-action GitHub ActionEPSS 1.1%CVE-2023-43322HIGHZPE Systems, Inc Nodegrid OS v5.0.0 to v5.0.17, v5.2.0 to v5.2.19, v5.4.0 to v5.4.16, v5.6.0 to v5.6.13, v5.8.0 to v5.8.10, and v5.10.0 to vEPSS 1.1%CVE-2024-12442CRITICALCommand injection in EnerSys AMPA versions 24.04 through 24.16, inclusiveEPSS 1.1%CVE-2024-43601HIGHVisual Studio Code for Linux Remote Code Execution VulnerabilityEPSS 1.1%CVE-2026-10279MEDIUMhiraishikentaro wezterm-mcp switch_pane/write_to_specific_pane wezterm_executor.ts os command injectionEPSS 1.1%CVE-2026-88622HIGHNUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php.EPSS 1.1%CVE-2025-50755MEDIUMWavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_cmd function via the command parameter. This EPSS 1.1%CVE-2026-19333MEDIUMNightTrek Supabase-MCP generate_types command injectionEPSS 1.1%CVE-2026-81562MEDIUMAlexGladkov claude-in-mobile client.ts execSync os command injectionEPSS 1.1%CVE-2026-15193MEDIUMAidanPark openclaw-android Android WebView Bridge JsBridge.kt os command injectionEPSS 1.1%CVE-2026-15669MEDIUMlouisho5 picobot exec Tool exec.go ExecTool.Execute os command injectionEPSS 1.1%CVE-2026-4199MEDIUMbazinga012 mcp_code_executor index.ts installDependencies command injectionEPSS 1.1%CVE-2026-16631MEDIUMpublint package-manager pack.js child_process.exec os command injectionEPSS 1.1%CVE-2026-5603MEDIUMelgentos magento2-dev-mcp index.ts executeMagerun2Command os command injectionEPSS 1.1%CVE-2026-16735MEDIUMrelease-it conventional-changelog Changelog File index.js writeChangelog os command injectionEPSS 1.1%CVE-2026-19329MEDIUMandreahaku codex_mcp ask MCP Tool codex-process-simple.ts command injectionEPSS 1.1%CVE-2026-16629MEDIUMdanger danger-js CLI localGetFileAtSHA.ts danger.git.diffForFile os command injectionEPSS 1.1%CVE-2026-5007MEDIUMkazuph mcp-docs-rag add_git_repository/add_text_file index.ts cloneRepository os command injectionEPSS 1.1%