Weaknesses of type CWE-78

4,627 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-25828MEDIUMgrub-btrfs through 2026-01-31 (on Arch Linux and derivative distributions) allows initramfs OS command injection because it does not sanitizEPSS 1.4%CVE-2023-25925HIGHIBM Security Guardium Key Lifecycle Manager command injectionEPSS 1.4%CVE-2025-34150CRITICALShenzhen Aitemi M300 Wi-Fi Repeater PPPoE Username Command InjectionEPSS 1.4%CVE-2026-40711HIGHDell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-powermax v2.16.0, contEPSS 1.3%CVE-2022-31486HIGHCommand injection via Advanced Networking route add functionalityEPSS 1.3%CVE-2024-50359HIGHA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.3%CVE-2026-21571CRITICALThis Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0,EPSS 1.3%CVE-2025-28036CRITICALTOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function EPSS 1.3%CVE-2025-28035CRITICALTOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function tEPSS 1.3%CVE-2025-28034CRITICALTOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000REPSS 1.3%CVE-2024-12970LOWOS Command Injection in TUBITAK BILGEM's Pardus OS My ComputerEPSS 1.3%CVE-2023-40581HIGHyt-dlp command injection when using `%q` in `--exec` on WindowsEPSS 1.3%CVE-2026-65096HIGHNVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS command injection. EPSS 1.3%CVE-2021-21412MEDIUM[thi.ng/egf] Potential arbitrary code execution of `#gpg`-tagged property valuesEPSS 1.3%CVE-2026-65099HIGHNVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS command injection. A succEPSS 1.3%CVE-2026-65089HIGHNVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could cause OS command injectioEPSS 1.3%CVE-2026-0273MEDIUMPAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UIEPSS 1.3%CVE-2024-7203HIGHA post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.60 through V5.38 and USG FLEX series firEPSS 1.3%CVE-2024-42060HIGHA post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmwaEPSS 1.3%CVE-2024-42059HIGHA post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V5.00 through V5.38, USG FLEX series firmwaEPSS 1.3%