Weaknesses of type CWE-78

4,662 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2025-54415CRITICALdag-factory's CI/CD Workflow Allows for Repository Takeover and Secret ExfiltrationEPSS 0.7%CVE-2026-28460MEDIUMOpenClaw < 2026.2.22 - Allowlist Bypass via Shell Line-Continuation Command Substitution in system.runEPSS 0.7%CVE-2026-78569HIGHLangflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guardsEPSS 0.7%CVE-2026-9208HIGHTanium addressed an unauthorized code execution vulnerability in Connect.EPSS 0.7%CVE-2026-9207HIGHTanium addressed an unauthorized code execution vulnerability in Connect.EPSS 0.7%CVE-2026-27626CRITICALOliveTin vulnerable to OS Command Injection via `password` argument type and webhook JSON extraction bypasses shell safety checksEPSS 0.7%CVE-2026-34158HIGHCoolify: Command injection via single-quote breakout in Docker Compose custom commandsEPSS 0.7%CVE-2024-42370HIGHLitestar repository vulnerable to Environment Variable injection in `docs-preview.yml` workflowEPSS 0.7%CVE-2026-88277HIGHGV-LPCLPC2011/2211 - ONVIF Subscribe Address Command InjectionEPSS 0.7%CVE-2026-55897HIGHluci-app-advanced-reboot read ACL exposes /bin/sh through file.exec, allowing delegated users to run commands as rootEPSS 0.7%CVE-2026-73294CRITICALSemaphore U: OS Command InjectionEPSS 0.7%CVE-2026-42204HIGHCoolify: Authenticated RCE via SHELL_SAFE_COMMAND_PATTERN regression → host rootEPSS 0.7%CVE-2026-42153HIGHCoolify: PostgreSQL Healthcheck Command Injection Allows Root Code Execution in ContainerEPSS 0.7%CVE-2026-34058HIGHCoolify: OS Command Injection via Unmanaged Container Operations - Remote Code ExecutionEPSS 0.7%CVE-2026-72869CRITICALDokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCEEPSS 0.7%CVE-2026-72872CRITICALDokploy: OS Command Injection via Bitbucket `owner`/`repository` in `git clone`EPSS 0.7%CVE-2026-73263CRITICALProwler: RCE on Prowler App workers via kubeconfig auth-provider cmd-pathEPSS 0.7%CVE-2026-82412HIGHntopng: Remote Code Execution via OS Command Injection in Vulnerability-Scan REST APIEPSS 0.7%CVE-2026-72865CRITICALDokploy: OS Command Injection via compose `composePath`EPSS 0.7%CVE-2024-36491CRITICALFutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allow an administrative user to execute an arbitrary OEPSS 0.7%