Weaknesses of type CWE-78

4,653 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2021-42852HIGHA command injection vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an authenticated user to execuEPSS 0.8%CVE-2026-1665MEDIUMCommand Injection in nvm via NVM_AUTH_HEADER in wget code pathEPSS 0.8%CVE-2026-49255HIGHelecterm: Command Injection in File System Operations (rmrf, mv, cp)EPSS 0.8%CVE-2026-45558CRITICALRoxy-WI: Authenticated RCE on every managed HAProxy load balancer via `option` field config injection in section saveEPSS 0.8%CVE-2021-26115HIGHAn OS command injection (CWE-78) vulnerability in FortiWAN version 4.5.7 and below Command Line Interface may allow a local, authenticated aEPSS 0.8%CVE-2024-46330HIGHVONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the iptablesWebsFilterRun object.EPSS 0.8%CVE-2017-6707—A vulnerability in the CLI command-parsing code of the Cisco StarOS operating system for Cisco ASR 5000 Series 11.0 through 21.0, 5500 SerieEPSS 0.8%CVE-2024-56137MEDIUMMaxKB RCE vulnerability in function libraryEPSS 0.8%CVE-2026-42143HIGHCoolify: OS Command Injection via Persistent Volume Names - Root RCE on Managed ServersEPSS 0.8%CVE-2026-72738CRITICALDokploy: Authenticated RCE via Command Injection in backup.listBackupFiles search ParameterEPSS 0.8%CVE-2026-72740CRITICALDokploy: OS Command Injection via SSH-form `customGitUrl` domain in `ssh-keyscan`EPSS 0.8%CVE-2026-0980HIGHRubyipmi: red hat satellite: remote code execution in rubyipmi via malicious bmc usernameEPSS 0.8%CVE-2026-26899HIGHAn issue was discovered in luci-app-https-dns-proxy on OpenWrt PR #15 (< 2026-01-17). The setInitAction function in /usr/libexec/rpcd/luci.hEPSS 0.8%CVE-2024-38889CRITICALAn issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker tEPSS 0.8%CVE-2026-34168HIGHCoolify: Command injection via unsanitized persistent storage name in docker volume commandsEPSS 0.8%CVE-2026-52891CRITICALWekan: Shell Injection via Avatar UploadEPSS 0.8%CVE-2026-34153HIGHCoolify LocalFileVolume fs_path command injection enables RCEEPSS 0.8%CVE-2026-34034HIGHCoolify: Host RCE via Sentinel token injectionEPSS 0.8%CVE-2026-3014MEDIUMRemote Code Execution by administrative user on the Management ServerEPSS 0.8%CVE-2024-41585MEDIUMDrayTek Vigor3910 devices through 4.3.2.6 are affected by an OS command injection vulnerability that allows an attacker to leverage the recvEPSS 0.8%