Weaknesses of type CWE-78

4,664 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2022-48684HIGHAn issue was discovered in Logpoint before 7.1.1. Template injection was seen in the search template. The search template uses jinja templatEPSS 0.6%CVE-2025-12744HIGHAbrt: command-injection in abrt leading to local privilege escalationEPSS 0.6%CVE-2025-53542HIGHKubernetes Headlamp Allows Arbitrary Command Injection in macOS Process headlamp@codeSignEPSS 0.6%CVE-2026-59960HIGHArgos JavaScript: CI Branch Name OS Command Injection in @argos-ci/coreEPSS 0.6%CVE-2026-3821HIGHSupermicro SMASH service contain an Arbitrary code execution issueEPSS 0.6%CVE-2026-52484HIGHAn issue in MitraStar GPT-2742GX4X5v6-SV GL_g2.5_100XNT0b23_3 allows an authenticated attacker to execute arbitrary code via the /cgi-bin/deEPSS 0.6%CVE-2026-22176MEDIUMOpenClaw < 2026.2.19 - Command Injection via Unescaped Environment Variables in Windows Scheduled Task Script GenerationEPSS 0.6%CVE-2024-13502CRITICALA command injection in the NTC2218, NTC2250, NTC2299 modems' web interfaces allows to exeucte arbitrary shell commands.EPSS 0.6%CVE-2026-84832HIGHUnsafe deserialization in the REST interfaceEPSS 0.6%CVE-2024-34013HIGHLocal privilege escalation due to OS command injection vulnerability. The following products are affected: Acronis True Image (macOS) beforeEPSS 0.6%CVE-2024-52058HIGHPotential arbitrary command execution in System Designer while parsing malicious HTTP/REST requestsEPSS 0.6%CVE-2026-34937HIGHPraisonAI: Shell Injection in run_python() via Unescaped $() SubstitutionEPSS 0.6%CVE-2026-80442CRITICALIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.6%CVE-2026-55975HIGHH.VIEW HV-500S6 IP Camera OS Command InjectionEPSS 0.6%CVE-2026-20266CRITICALOS Command Injection in the btool Configuration Helper in Splunk AI ToolkitEPSS 0.6%CVE-2026-25722HIGHClaude Code Vulnerable to Command Injection via Directory Change Bypasses Write ProtectionEPSS 0.6%CVE-2023-47540MEDIUMAn improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 tEPSS 0.6%CVE-2026-72739MEDIUMDokploy: Command Injection via Compose Shell ExecutionEPSS 0.6%CVE-2026-22179HIGHOpenClaw < 2026.2.22 - Allowlist Bypass via Command Substitution in system.runEPSS 0.6%CVE-2024-40587MEDIUMAn improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiVoice EPSS 0.6%