Weaknesses of type CWE-78

4,662 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-40852HIGHCommand injection via malicious configurationEPSS 0.7%CVE-2023-4856HIGH A format string vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute arbitrary commands on a EPSS 0.7%CVE-2026-73753HIGHAuthenticated Remote Command Injection Vulnerabilities in AOS-CX Command Line InterfaceEPSS 0.7%CVE-2026-14499HIGHLangflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpointsEPSS 0.7%CVE-2023-28906HIGHCommand injection in networking serviceEPSS 0.7%CVE-2025-26074CRITICALOrkes Conductor v3.21.11 allows remote attackers to execute arbitrary OS commands through unrestricted access to Java classes.EPSS 0.7%CVE-2019-1699MEDIUMCisco Firepower Threat Defense Software Command Injection VulnerabilityEPSS 0.7%CVE-2024-39228CRITICALGL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16,EPSS 0.7%CVE-2026-32298HIGHAngeet ES3 KVM OS command injectionEPSS 0.7%CVE-2026-5967HIGHTeamT5|ThreatSonar Anti-Ransomware - Privilege EscalationEPSS 0.7%CVE-2026-53542HIGHTermix: Tar option injection in file-manager archive creation allows command execution on managed SSH hostsEPSS 0.7%CVE-2026-22277HIGHDell UnityVSA, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InjectEPSS 0.7%CVE-2026-56004CRITICALobs-service-tar_scm: command injection via mercurial handlerEPSS 0.7%CVE-2026-21418HIGHDell Unity, version(s) 5.5.2 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InjectiEPSS 0.7%CVE-2022-45939HIGHGNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etagEPSS 0.7%CVE-2024-51465HIGHIBM App Connect Enterprise Certified Container command executionEPSS 0.7%CVE-2024-47608MEDIUMLogicytics vulnerable to shell injectionsEPSS 0.7%CVE-2025-37158MEDIUMAuthenticated Command Injection allows Unauthorized Command Execution in AOS-CXEPSS 0.7%CVE-2025-37157MEDIUMAuthenticated Command Injection allows Unauthorized Command Execution in AOS-CXEPSS 0.7%CVE-2025-54415CRITICALdag-factory's CI/CD Workflow Allows for Repository Takeover and Secret ExfiltrationEPSS 0.7%