Weaknesses of type CWE-78

4,664 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-24887HIGHClaude Code has a Command Injection in find Command Bypasses User Approval PromptEPSS 0.6%CVE-2026-44055HIGHBitwise OR logic bug enables shell injectionEPSS 0.6%CVE-2025-62713HIGHKottster app reinitialization can be re-triggered allowing command injection in development modeEPSS 0.6%CVE-2025-60803CRITICALAntabot White-Jotter up to commit 9bcadc was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the compEPSS 0.6%CVE-2026-86108HIGHSecurity Advisory 0181EPSS 0.6%CVE-2022-4515HIGHA flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename spEPSS 0.6%CVE-2024-32118MEDIUMMultiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet ForEPSS 0.6%CVE-2026-72884HIGHDokploy: Command Injection via Compose Custom CommandEPSS 0.6%CVE-2026-93012CRITICALEmail::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command execution on Windows sending a message whose envelope address reaches the shell in _sendmail_pipeEPSS 0.6%CVE-2026-55673HIGHPowSyBl: Command Injection in LocalCommandExecutor-sEPSS 0.6%CVE-2026-55420HIGHDiscourse: Remote code execution via pdf uploadsEPSS 0.6%CVE-2022-43948MEDIUMA improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 7.0.0 through 7.0.EPSS 0.6%CVE-2022-42433MEDIUMThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR841N TL-WR841N(US)_EPSS 0.6%CVE-2026-13336HIGHCWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause exeEPSS 0.6%CVE-2026-54674HIGHAuthenticated Command Injection in FreePBX UCP InterfaceEPSS 0.6%CVE-2018-25143HIGHMicrohard Systems IPn4G 1.1.0 Backdoor Jailbreak via Microhard Sh ServiceEPSS 0.6%CVE-2023-44277HIGH Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in EPSS 0.6%CVE-2024-56808LOWMedia Streaming add-onEPSS 0.6%CVE-2026-64625CRITICALAVideo before 29.0 OS Command Injection via execAsyncEPSS 0.6%CVE-2024-58286CRITICALdizqueTV 1.5.3 Remote Code Execution via FFMPEG Executable PathEPSS 0.6%