Weaknesses of type CWE-78

4,638 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2023-24958HIGHIBM TS7700 Management Interface command injectionEPSS 1.1%CVE-2025-30247CRITICALAn OS command injection vulnerability in user interface in Western Digital My Cloud firmware prior to 5.31.108 on NAS platforms allows remotEPSS 1.1%CVE-2026-22893HIGHQTS, QuTS heroEPSS 1.1%CVE-2026-10279MEDIUMhiraishikentaro wezterm-mcp switch_pane/write_to_specific_pane wezterm_executor.ts os command injectionEPSS 1.1%CVE-2023-27985HIGHemacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is relatedEPSS 1.1%CVE-2025-9573HIGHCommand Injection in extension "TYPO3 Backup Plus" (ns_backup)EPSS 1.1%CVE-2026-45018CRITICALChainlit: Command injection via MCP stdio transport allows unauthenticated remote code executionEPSS 1.1%CVE-2026-56137HIGHRPG MAKER MV and MZ provided by Gotcha Gotcha Games Inc. contain an OS command injection vulnerability. If a user loads a specially crafted EPSS 1.1%CVE-2026-59561HIGHSakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed tEPSS 1.1%CVE-2025-66208HIGHConfiguration-Dependent RCE (OS Command Injection) in richdocumentscode proxyEPSS 1.1%CVE-2022-43390MEDIUMA command injection vulnerability in the CGI program of Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated aEPSS 1.1%CVE-2026-16629MEDIUMdanger danger-js CLI localGetFileAtSHA.ts danger.git.diffForFile os command injectionEPSS 1.1%CVE-2026-16631MEDIUMpublint package-manager pack.js child_process.exec os command injectionEPSS 1.1%CVE-2026-16489MEDIUMjsforce SFDX Connection Registry sfdx.js _execCommand os command injectionEPSS 1.1%CVE-2026-15193MEDIUMAidanPark openclaw-android Android WebView Bridge JsBridge.kt os command injectionEPSS 1.1%CVE-2026-78430MEDIUMsworddut mcp-ffmpeg-helper Tool handlers.ts handleToolCall os command injectionEPSS 1.1%CVE-2026-15669MEDIUMlouisho5 picobot exec Tool exec.go ExecTool.Execute os command injectionEPSS 1.1%CVE-2026-5007MEDIUMkazuph mcp-docs-rag add_git_repository/add_text_file index.ts cloneRepository os command injectionEPSS 1.1%CVE-2026-3959MEDIUM0xKoda WireMCP Tshark CLI index.js server.tool os command injectionEPSS 1.1%CVE-2026-81562MEDIUMAlexGladkov claude-in-mobile client.ts execSync os command injectionEPSS 1.1%