Weaknesses of type CWE-78

4,653 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2022-27486MEDIUMA improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiDDoS version 5.5.0 through 5.5EPSS 0.8%CVE-2020-37002HIGHAjenti 2.1.36 Authenticated Remote Code ExecutionEPSS 0.8%CVE-2026-101045HIGHFleet Homebrew Cask OS Command Injection via MetadataEPSS 0.8%CVE-2025-48204MEDIUMThe ns_backup extension through 13.0.0 for TYPO3 allows command injection.EPSS 0.8%CVE-2026-17497HIGHNoteGen arbitrary OS command execution via Tauri shell:allow-execute for bash/pythonEPSS 0.7%CVE-2021-4029HIGHA command injection vulnerability in the CGI program of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary OS commaEPSS 0.7%CVE-2025-57771HIGHRoo-Code potential remote code execution via auto-execute command parsing flawEPSS 0.7%CVE-2025-31693MEDIUMAI (Artificial Intelligence) - Moderately critical - Gadget Chain - SA-CONTRIB-2025-022EPSS 0.7%CVE-2024-43402HIGHRust OS Command Injection/Argument Injection vulnerabilityEPSS 0.7%CVE-2025-27262HIGHEricsson Indoor Connect 8855 - Improper Neutralization of Special Elements used in an OS Command VulnerabilityEPSS 0.7%CVE-2023-34215HIGHSecond Order Command-injection Vulnerability in the Certificate-generation FunctionEPSS 0.7%CVE-2026-32311CRITICALCommand Injection and Docker container escape allows root on host machineEPSS 0.7%CVE-2024-46890CRITICALA vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate inpEPSS 0.7%CVE-2026-0758HIGHmcp-server-siri-shortcuts shortcutName Command Injection Privilege Escalation VulnerabilityEPSS 0.7%CVE-2026-54699HIGHWarp: OS command injection when opening terminal links from WSLEPSS 0.7%CVE-2024-43385HIGHPhoenix Contact: OS command execution through PROXY_HTTP_PORT in mGuard devicesEPSS 0.7%CVE-2024-43386HIGHPhoenix Contact: OS command execution through EMAIL_NOTIFICATION.TO in mGuard devices.EPSS 0.7%CVE-2025-60959HIGHOS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers tEPSS 0.7%CVE-2025-60962HIGHOS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers tEPSS 0.7%CVE-2026-73483CRITICALFlowise before 3.1.3 Sandbox Escape via PuppeteerEPSS 0.7%