Weaknesses of type CWE-78

4,653 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2024-41585MEDIUMDrayTek Vigor3910 devices through 4.3.2.6 are affected by an OS command injection vulnerability that allows an attacker to leverage the recvEPSS 0.8%CVE-2026-66138HIGHIn OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a runniEPSS 0.8%CVE-2026-54182HIGHbackpack/crud: OS command injection in Stats::makeCurlRequest via attacker-controlled Host header (pre-auth)EPSS 0.8%CVE-2026-49980CRITICALRclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fixEPSS 0.8%CVE-2026-41411MEDIUMVim: Command injection via backtick expansion in tag filenamesEPSS 0.8%CVE-2025-66203CRITICALStreamVault is Vulnerable to Authenticated Remote Code Execution (RCE) via ytdlpargs Configuration InjectionEPSS 0.8%CVE-2026-33641HIGHGlances Vulnerable to Command Injection via Dynamic Configuration ValuesEPSS 0.8%CVE-2024-58338HIGHAnevia Flamingo XL 3.2.9 Remote Root Jailbreak via Traceroute CommandEPSS 0.8%CVE-2024-42029MEDIUMxdg-desktop-portal-hyprland (aka an XDG Desktop Portal backend for Hyprland) before 1.3.3 allows OS command execution, e.g., because single EPSS 0.8%CVE-2021-33633HIGHCommand Injection in aops-ceresEPSS 0.8%CVE-2026-82887HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.8%CVE-2023-37032HIGHA Stack-based buffer overflow in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5EPSS 0.8%CVE-2026-73660HIGHFreePBX: Authenticated TTS AGI Command Injection Through TTS NameEPSS 0.8%CVE-2024-49803CRITICALIBM Security Verify Access Appliance command executionEPSS 0.8%CVE-2026-41497CRITICALIncomplete fix for CVE-2026-34935: Command Injection in MervinPraison/PraisonAIEPSS 0.8%CVE-2023-42122HIGHControl Web Panel wloggui Command Injection Local Privilege Escalation VulnerabilityEPSS 0.8%CVE-2023-46510—An issue in ZIONCOM (Hong Kong) Technology Limited A7000R v.4.1cu.4154 allows an attacker to execute arbitrary code via the cig-bin/cstecgi.EPSS 0.8%CVE-2026-47751MEDIUMClaude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret ExfiltrationEPSS 0.8%CVE-2024-28748HIGHifm: Reading function in Smart PLC allows command injections EPSS 0.8%CVE-2026-4946HIGHNSA Ghidra Auto-Analysis Annotation Command ExecutionEPSS 0.8%