Weaknesses of type CWE-77

2,823 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2025-52995HIGHFile Browser vulnerable to command execution allowlist bypassEPSS 0.6%CVE-2025-23170MEDIUMThe Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the Director shell via SEPSS 0.6%CVE-2024-53526MEDIUMcomposio >=0.5.40 is vulnerable to Command Execution in composio_openai, composio_claude, and composio_julep via the handle_tool_calls functEPSS 0.6%CVE-2026-30624HIGHAgent Zero 0.9.8 contains a remote code execution vulnerability in its External MCP Servers configuration feature. The application allows usEPSS 0.6%CVE-2025-67436MEDIUMAuthenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inject a malicious PHP EPSS 0.6%CVE-2024-42348CRITICALFOG leaks sensitive information (AD domain, username and password)EPSS 0.6%CVE-2020-13712HIGHMGOS Command InjectionEPSS 0.6%CVE-2025-40937HIGHA vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application do not properly validate input paraEPSS 0.6%CVE-2024-53305HIGHAn issue in the component /models/config.py of Whoogle search v0.9.0 allows attackers to execute arbitrary code via supplying a crafted searEPSS 0.6%CVE-2024-42360CRITICALCommand Injection in sequenceserverEPSS 0.6%CVE-2025-27211HIGHAn Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.10.4 and earlier) could allow a Command Injection by a malicious actor with acEPSS 0.6%CVE-2025-29509HIGHJan v0.5.14 and before is vulnerable to remote code execution (RCE) when the user clicks on a rendered link in the conversation, due to openEPSS 0.6%CVE-2026-23652CRITICALMicrosoft Power Pages Remote Code Execution VulnerabilityEPSS 0.6%CVE-2024-46089MEDIUM74cms <=3.33 is vulnerable to remote code execution (RCE) in the background interface apiadmin.EPSS 0.6%CVE-2025-59272CRITICALCopilot Information Disclosure VulnerabilityEPSS 0.6%CVE-2025-59252CRITICALM365 Copilot Information Disclosure VulnerabilityEPSS 0.6%CVE-2025-59286CRITICALCopilot Information Disclosure VulnerabilityEPSS 0.6%CVE-2026-10195HIGHFS Poster <= 8.0.1 - Authenticated (Subscriber+) Remote Code Execution via FFmpeg Path SettingEPSS 0.6%CVE-2026-40068HIGHClaude Code arbitrary code execution via git worktree commondir trust dialog bypassEPSS 0.6%CVE-2024-57036HIGHTOTOLINK A810R V4.1.2cu.5032_B20200407 was found to contain a command insertion vulnerability in downloadFile.cgi main function. This vulnerEPSS 0.6%