Weaknesses of type CWE-77

2,819 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2026-35580CRITICALEmissary has GitHub Actions Shell Injection via Workflow InputsEPSS 0.7%CVE-2025-45619MEDIUMAn issue in Aver PTC310UV2 firmware v.0.1.0000.59 allows a remote attacker to execute arbitrary code via the SendAction functionEPSS 0.7%CVE-2024-24550HIGHBludit - Remote Code Execution (RCE) through File APIEPSS 0.7%CVE-2024-57214MEDIUMTOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifEPSS 0.7%CVE-2023-50274HIGHHPE OneView may allow command injection with local privilege escalation.EPSS 0.7%CVE-2025-46816CRITICALgoshs route not protected, allows command executionEPSS 0.7%CVE-2024-57213MEDIUMTOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the newpasswd parameter in the action_EPSS 0.7%CVE-2025-66032HIGHClaude Code Command Validation Bypass Allows Arbitrary Code ExecutionEPSS 0.7%CVE-2025-67728CRITICALFireshare Public Uploads feature is vulnerable to OS Command Injection (RCE)EPSS 0.7%CVE-2023-4401HIGH Dell SmartFabric Storage Software v1.4 (and earlier) contains an OS Command Injection Vulnerability in the CLI use of the ‘more’ command. AEPSS 0.7%CVE-2026-22864HIGHDeno has an incomplete fix for command-injection prevention on Windows — case-insensitive extension bypassEPSS 0.7%CVE-2024-41134HIGHAuthenticated Remote Code Execution in HPE Aruba Networking EdgeConnect SD-WAN Command Line InterfaceEPSS 0.7%CVE-2024-43497HIGHDeepSpeed Remote Code Execution VulnerabilityEPSS 0.7%CVE-2017-12341—A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attackEPSS 0.7%CVE-2024-48153CRITICALDrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the EPSS 0.7%CVE-2026-88765HIGHImproper Neutralization of Special Elements used in a Command ('Command Injection') in GitLabEPSS 0.7%CVE-2023-26294HIGHPrevious versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.EPSS 0.7%CVE-2024-54802CRITICALIn Netgear WNR854T 1.5.2 (North America), the UPNP service (/usr/sbin/upnp) is vulnerable to stack-based buffer overflow in the M-SEARCH HosEPSS 0.7%CVE-2025-48978HIGHAn Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.11.0 and earlier) could allow a Command Injection by a malicious actor with acEPSS 0.7%CVE-2022-35954MEDIUMDelimiter injection vulnerability in @actions/core exportVariableEPSS 0.7%