Weaknesses of type CWE-77

2,819 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2026-54449HIGHLangBot: Authenticated RCE Via MCP ConfigurationEPSS 0.7%CVE-2024-1417HIGHLocal Code Injection Vulnerability in AuthPoint Password Manager App for macOS SafariEPSS 0.7%CVE-2023-47268MEDIUMIn libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrary code on a host wheEPSS 0.7%CVE-2026-85885CRITICALMicrosoft 365 Copilot Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2023-47104CRITICALtinyfiledialogs (aka tiny file dialogs) before 3.15.0 allows shell metacharacters (such as a backquote or a dollar sign) in titles, messagesEPSS 0.7%CVE-2026-20096MEDIUMCisco Integrated Management Controller Command Injection VulnerabilityEPSS 0.7%CVE-2026-30617HIGHLangChain-ChatChat 0.3.1 contains a remote code execution vulnerability in its MCP STDIO server configuration and execution handling. A remoEPSS 0.7%CVE-2026-79754HIGHNuclio: Kaniko build tempDir command injectionEPSS 0.7%CVE-2025-53787HIGHMicrosoft 365 Copilot BizChat Information Disclosure VulnerabilityEPSS 0.7%CVE-2021-1382MEDIUMCisco IOS XE SD-WAN Software Command Injection VulnerabilityEPSS 0.7%CVE-2025-23119HIGHAn Improper Neutralization of Escape Sequences vulnerability could allow an Authentication Bypass with a Remote Code Execution (RCE) by a maEPSS 0.7%CVE-2026-42893HIGHMicrosoft Outlook for iOS Tampering VulnerabilityEPSS 0.7%CVE-2026-42895MEDIUMMicrosoft Copilot Tampering VulnerabilityEPSS 0.7%CVE-2026-8431CRITICALOps Manager RCE via webhook bodyEPSS 0.7%CVE-2024-7575HIGHImproper neutralization special element in hyperlinksEPSS 0.7%CVE-2023-47356HIGHMingyu Security Gateway before v3.0-5.3p was discovered to contain a remote command execution (RCE) vulnerability via the log_type parameterEPSS 0.7%CVE-2017-12339—A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attackEPSS 0.7%CVE-2025-22473HIGHDell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special ElementsEPSS 0.7%CVE-2024-49194HIGHDatabricks JDBC Driver 2.x before 2.6.40 could potentially allow remote code execution (RCE) by triggering a JNDI injection via a JDBC URL pEPSS 0.7%CVE-2024-49557HIGHDell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Improper Neutralization of Special ElementsEPSS 0.7%