Weaknesses of type CWE-77

2,820 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2025-57164MEDIUMFlowise through v3.0.4 is vulnerable to remote code execution via unsanitized evaluation of user input in the "Supabase RPC Filter" field.EPSS 0.6%CVE-2023-33298—com.perimeter81.osx.HelperTool in Perimeter81 10.0.0.19 on macOS allows Local Privilege Escalation (to root) via shell metacharacters in usiEPSS 0.6%CVE-2019-1893HIGHCisco Enterprise NFV Infrastructure Software Command Injection VulnerabilityEPSS 0.6%CVE-2025-66738HIGHAn issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a crafted request the EPSS 0.6%CVE-2025-43012HIGHIn JetBrains Toolbox App before 2.6 command injection in SSH plugin was possibleEPSS 0.6%CVE-2024-0005CRITICALA condition exists in FlashArray and FlashBlade Purity whereby a malicious user could execute arbitrary commands remotely through a specificEPSS 0.6%CVE-2021-31357HIGHJunos OS Evolved: shell-injection vulnerabilities in evo_tcpdump UI wrapper scriptEPSS 0.6%CVE-2025-25692MEDIUMA PHAR deserialization vulnerability in the _getHeaders function of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a craftEPSS 0.6%CVE-2026-72736CRITICALDokploy: OS Command Injection in registry credential testing and Swarm cluster management → HOST RCEEPSS 0.6%CVE-2020-1980HIGHPAN-OS: Shell injection vulnerability in PAN-OS CLI allows execution of shell commandsEPSS 0.6%CVE-2025-53098HIGHRoo Code Vulnerable to Potential Remote Code Execution via Model Context ProtocolEPSS 0.6%CVE-2024-40445HIGHA directory traversal vulnerability in forkosh Mime TeX before version 1.77 allows attackers on Windows systems to read or append arbitrary EPSS 0.6%CVE-2021-31358HIGHJunos OS Evolved: shell-injection vulnerabilities in evo_sftp UI wrapper scriptEPSS 0.6%CVE-2024-51260CRITICALDrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the EPSS 0.6%CVE-2024-28041HIGHHGW BL1500HM Ver 002.001.013 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary command.EPSS 0.6%CVE-2021-38116HIGHPossible Command injection Vulnerability in OpenText iManagerEPSS 0.6%CVE-2026-81380MEDIUMGitHub Copilot and Visual Studio Code Information Disclosure VulnerabilityEPSS 0.6%CVE-2025-11921HIGHiStat Menus 7.10.4 - Local Privilege EscalationEPSS 0.6%CVE-2025-32702HIGHVisual Studio Remote Code Execution VulnerabilityEPSS 0.6%CVE-2025-55283CRITICALaiven-db-migrate allows Privilege Escalation through use of psql during migrationEPSS 0.6%