Weaknesses of type CWE-77

2,825 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2026-23814HIGHAuthenticated Command Injection found in AOS-CX CLI CommandEPSS 0.6%CVE-2024-33439CRITICALAn issue in Kasda LinkSmart Router KW5515 v1.7 and before allows an authenticated remote attacker to execute arbitrary OS commands via cgi pEPSS 0.6%CVE-2024-58354HIGHcal.com Repository Takeover via pull_request_target WorkflowEPSS 0.6%CVE-2023-49716MEDIUMEmerson Rosemount GC370XA, GC700XA, GC1500XA Command InjectionEPSS 0.6%CVE-2024-53412HIGHCommand injection in the connect function in NietThijmen ShoppingCart 0.0.2 allows an attacker to execute arbitrary shell commands and achieEPSS 0.6%CVE-2020-3266HIGHCisco SD-WAN Solution Command Injection VulnerabilityEPSS 0.6%CVE-2024-48145CRITICALA prompt injection vulnerability in the chatbox of Netangular Technologies ChatNet AI Version v1.0 allows attackers to access and exfiltrateEPSS 0.6%CVE-2024-48144CRITICALA prompt injection vulnerability in the chatbox of Fusion Chat Chat AI Assistant Ask Me Anything v1.2.4.0 allows attackers to access and exfEPSS 0.6%CVE-2024-51258HIGHDrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the EPSS 0.6%CVE-2026-41265CRITICALFlowise: Airtable_Agent Code Injection Remote Code Execution VulnerabilityEPSS 0.6%CVE-2024-54660HIGHA JNDI injection issue was discovered in Cloudera JDBC Connector for Hive before 2.6.26 and JDBC Connector for Impala before 2.6.35. AttackeEPSS 0.6%CVE-2024-20492MEDIUMCisco Expressway Series Privilege Escalation VulnerabilityEPSS 0.6%CVE-2025-46735LOWTerraform WinDNS Provider improperly sanitizes input variables in `windns_record`EPSS 0.6%CVE-2025-22476MEDIUMDell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Neutralization of Special Elements used in a Command EPSS 0.5%CVE-2021-0253HIGHJunos OS: NFX Series: Local Command Execution Vulnerability in JDMD Leads to Privilege EscalationEPSS 0.5%CVE-2025-24861HIGHOutback Power Mojave Inverter Command InjectionEPSS 0.5%CVE-2020-11073HIGHRemote Code Execution in Autoswitch Python VirtualenvEPSS 0.5%CVE-2026-26133HIGHM365 Copilot Information Disclosure VulnerabilityEPSS 0.5%CVE-2024-38641HIGHQTS, QuTS heroEPSS 0.5%CVE-2026-44257CRITICALefw4.X: RCE via zipslipEPSS 0.5%