Weaknesses of type CWE-77

2,816 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2025-2730HIGHH3C Magic BE18000 HTTP POST Request getssidname command injectionEPSS 1.0%CVE-2025-2731HIGHH3C Magic BE18000 HTTP POST Request getDualbandSync command injectionEPSS 1.0%CVE-2025-2728HIGHH3C Magic NX30 Pro/Magic NX400 getNetworkConf command injectionEPSS 1.0%CVE-2026-76233HIGHRenovate 39.53.0 before 40.33.0 Command Injection via gleam managerEPSS 1.0%CVE-2026-76229HIGHRenovate 39.218.0 before 40.33.0 Arbitrary Command Injection via kustomizeEPSS 1.0%CVE-2020-5299MEDIUMPotential CSV Injection vector in OctoberCMSEPSS 1.0%CVE-2024-52022HIGHNetgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a command injection vulnerabEPSS 1.0%CVE-2024-44577HIGHRELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the time_date function.EPSS 1.0%CVE-2026-22317HIGHCommand Injection Vulnerability in Root CA Certificate Transfer WorkflowEPSS 1.0%CVE-2024-36983HIGHCommand Injection using External LookupsEPSS 1.0%CVE-2022-25962HIGHAll versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization. EPSS 1.0%CVE-2026-56197HIGHWindows Admin Center (WAC) Remote Code Execution VulnerabilityEPSS 1.0%CVE-2023-26127HIGHAll versions of the package n158 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports' function. *EPSS 1.0%CVE-2025-61489MEDIUMA command injection vulnerability in the shell_exec function of sonirico mcp-shell v0.3.1 allows attackers to execute arbitrary commands viaEPSS 1.0%CVE-2024-8640HIGHImproper Neutralization of Special Elements used in a Command ('Command Injection') in GitLabEPSS 1.0%CVE-2024-13062HIGHAn unintended entry point vulnerability has been identified in certain router models, which may allow for arbitrary command execution. ReferEPSS 1.0%CVE-2024-3483HIGHRemote Code Execution vulnerability in the iManagerEPSS 1.0%CVE-2025-57282HIGHngrok v4.3.3 and 5.0.0-beta.2 is vulnerable to Command Injection.EPSS 1.0%CVE-2024-6257HIGHHashiCorp go-getter Vulnerable to Code Execution On Git Update Via Git Config ManipulationEPSS 1.0%CVE-2025-0396HIGHexelban stats XPC Service shouldAcceptNewConnection command injectionEPSS 1.0%