Weaknesses of type CWE-78

4,640 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-76690HIGHAuthenticated Remote Code Execution Vulnerability in HPE Networking EdgeConnect SD-WAN GatewaysEPSS 1.1%CVE-2025-43978HIGHJointelli 5G CPE 21H01 firmware JY_21H01_A3_v1.36 devices allow (blind) OS command injection. Multiple endpoints are vulnerable, including /EPSS 1.1%CVE-2026-73769HIGHAuthenticated Remote Code Execution in CPPM Web InterfaceEPSS 1.1%CVE-2025-69262HIGHpnpm vulnerable to Command Injection via environment variable substitutionEPSS 1.1%CVE-2022-25906HIGHAll versions of the package is-http2 are vulnerable to Command Injection due to missing input sanitization or other checks, and sandboxes beEPSS 1.1%CVE-2025-55589MEDIUMTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain multiple OS command injection vulnerabilities via the macstr, bandstr, and cEPSS 1.1%CVE-2025-22469MEDIUMOS command injection vulnerability exists in CL4/6NX Plus and CL4/6NX-J Plus (Japan model) with the firmware versions prior to 1.15.5-r1. AnEPSS 1.1%CVE-2024-2243HIGHCsmock: command injection vulnerability in csmock-plugin-snykEPSS 1.1%CVE-2026-39862MEDIUMTophat has a Command Injection Vulnerability When Accessing a Maliciously Crafted Tophat LinkEPSS 1.1%CVE-2026-32191CRITICALMicrosoft Bing Images Remote Code Execution VulnerabilityEPSS 1.1%CVE-2022-41871MEDIUMSEPPmail through 12.1.17 allows command injection within the Admin Portal. An authenticated attacker is able to execute arbitrary code in thEPSS 1.1%CVE-2025-1753HIGHCommand Injection in LLama-Index CLI in run-llama/llama_indexEPSS 1.1%CVE-2021-3725HIGHOS Command Injection in ohmyzsh/ohmyzshEPSS 1.1%CVE-2025-66279HIGHQTS, QuTS heroEPSS 1.1%CVE-2025-53472HIGHWRC-BE36QS-B and WRC-W701-B contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilEPSS 1.1%CVE-2024-24890HIGHCommand injection in ioprobe of gala-gopherEPSS 1.1%CVE-2025-66273HIGHQTS, QuTS heroEPSS 1.1%CVE-2026-15068CRITICALVulnerabilities in IBM AIX and PowerVM VIOSEPSS 1.1%CVE-2023-34975MEDIUMQTS, QuTS hero, QuTScloudEPSS 1.0%CVE-2026-77521CRITICALMaxKB: Prompt-injectable agent can lead to command executionEPSS 1.0%