Weaknesses of type CWE-78

4,664 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-100368HIGHCliInvoke.Specializations: Command injection in PowerShell and Cmd shell wrappersEPSS 0.6%CVE-2025-10622HIGHForeman: os command injection via ct_location and fcct_location parametersEPSS 0.6%CVE-2026-89139HIGHTemporal Server worker deployment compute provider executes a caller-supplied command on the Worker Service hostEPSS 0.6%CVE-2026-95521HIGHRpm: rpm: shell command injection via macro expansion of source/spec file basenames when installing a source rpmEPSS 0.6%CVE-2026-77601HIGHOpenC3 COSMOS: Authenticated OS command injection via the `pypi_url` settingEPSS 0.6%CVE-2024-10653HIGHCHANGING Information Technology IDExpert - OS Command InjectionEPSS 0.6%CVE-2026-86733HIGHSnipe-IT before 8.7.0 Remote Code Execution via Backup RestoreEPSS 0.6%CVE-2026-31067MEDIUMA remote command execution (RCE) vulnerability in the /goform/formReleaseConnect component of UTT Aggressive 520W v3v1.7.7-180627 allows attEPSS 0.6%CVE-2024-5400HIGHOpenfind Mail2000 - OS Command InjectionEPSS 0.6%CVE-2026-25623HIGHArista Edge Threat Management NGFW UI Arbitrary Command ExecutionEPSS 0.6%CVE-2026-17102HIGHDataStage on Cloud Pak for Data has several vulnerabilitiesEPSS 0.6%CVE-2022-38132HIGHCommand injection vulnerability in Linksys MR8300 router while Registration to DDNS Service. By specifying username and password, an attacker connected to the router's web interface can execute arbitrary OS commands.EPSS 0.6%CVE-2025-43940HIGHDell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InjectionEPSS 0.6%CVE-2025-43942HIGHDell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InjectionEPSS 0.6%CVE-2025-43939HIGHDell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InjectionEPSS 0.6%CVE-2025-46644MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.0.0, LTS2025 releaseEPSS 0.6%CVE-2025-23383HIGHDell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InjectionEPSS 0.6%CVE-2025-24380HIGHDell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InjectionEPSS 0.6%CVE-2024-49565HIGHDell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InjectionEPSS 0.6%CVE-2024-49564HIGHDell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InjectionEPSS 0.6%