Weaknesses of type CWE-78

4,623 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-1427HIGHWellChoose|Single Sign-On Portal System - OS Command InjectionEPSS 1.4%CVE-2026-24905MEDIUMInspektor Gadget has a Command Injection vulnerability in Makefile.buildEPSS 1.4%CVE-2025-34149CRITICALShenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via WPA2 KeyEPSS 1.4%CVE-2021-46686CRITICALImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in acmailer CGI ver.4.0.3 and earlieEPSS 1.4%CVE-2024-51024HIGHD-Link DIR_823G 1.0.2B05 was discovered to contain a command injection vulnerability via the HostName parameter in the SetWanSettings functiEPSS 1.4%CVE-2025-2367MEDIUMOiwtech OIW-2431APGN-HP Personal Script Submenu formScript os command injectionEPSS 1.4%CVE-2025-13943HIGHA post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware versions through 5.5EPSS 1.4%CVE-2021-44453CRITICALmySCADA myPROEPSS 1.4%CVE-2025-53818HIGHgithub-kanban-mcp-server Command Injection vulnerabilityEPSS 1.4%CVE-2026-65639CRITICALOS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured alloEPSS 1.4%CVE-2024-8686HIGHPAN-OS: Command Injection VulnerabilityEPSS 1.4%CVE-2026-4496MEDIUMsigmade Git-MCP-Server gitUtils.ts child_process.exec os command injectionEPSS 1.4%CVE-2026-22222HIGHCommand Injection Vulnerability on TP-Link Archer BE230 v1.2EPSS 1.4%CVE-2023-27988HIGHThe post-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.13)C0 could allow an autheEPSS 1.4%CVE-2026-5621MEDIUMChrisChinchilla Vale-MCP HTTP index.ts os command injectionEPSS 1.4%CVE-2026-5619MEDIUMBraffolk mcp-summarization-functions summarize_command mcp-server.ts os command injectionEPSS 1.4%CVE-2026-0785HIGHALGO 8180 IP Audio Alerter API Command Injection Remote Code Execution VulnerabilityEPSS 1.4%CVE-2025-68459HIGHRG - AP180, Indoor Wall Plate Wireless AP AP180 series provided by Ruijie Networks Co., Ltd. contain an OS command injection vulnerability. EPSS 1.4%CVE-2025-7451CRITICALHgiga|iSherlock - OS Command InjectionEPSS 1.4%CVE-2022-43536HIGHVulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands onEPSS 1.4%