Weaknesses of type CWE-78

4,664 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2025-9996MEDIUMCWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause theEPSS 0.5%CVE-2026-24129HIGHRuntipi is Vulnerable to Authenticated Arbitrary Remote Code ExecutionEPSS 0.5%CVE-2024-2421CRITICALLenelS2 NetBox Improper Neutralization of Special ElementsEPSS 0.5%CVE-2024-31668CRITICALrizin before v0.6.3 is vulnerable to Improper Neutralization of Special Elements via meta_set function in librz/analysis/meta.EPSS 0.5%CVE-2025-22605HIGHCoolify OS Command Injection Vulnerability in SSH Command GenerationEPSS 0.5%CVE-2026-71243HIGHbackmeup (npm) - OS Command Injection via Backup Option ValuesEPSS 0.5%CVE-2026-52483HIGHThe ping diagnostics and other similar functions of the MitraStar GPT-2741GNAC-N2-SV router with firmware BR_g8.10_1.11(WVK.0)b46 allow authEPSS 0.5%CVE-2026-45564HIGHRoxy-WI: Authenticated RCE via 'configver' URL parameter (os.system sink in /config/versions/.../save)EPSS 0.5%CVE-2026-72882CRITICALDokploy: Authenticated blind command injection via file mounts leads to direct remote host RCE on managed serversEPSS 0.5%CVE-2026-16793HIGHRemote Command Injection via OS Profile Password in Lenovo XClarity OrchestratorEPSS 0.5%CVE-2023-7338HIGHRuckus Unleashed Authenticated RCE in Gateway ModeEPSS 0.5%CVE-2024-20275MEDIUMCisco Secure Firewall Management Center Software Backup Cluster Command Injection VulnerabilityEPSS 0.5%CVE-2026-34940HIGHKubeAI has an OS Command Injection via Model URL in Ollama Engine startup probe allows arbitrary command execution in model podsEPSS 0.5%CVE-2019-15274MEDIUMCisco TelePresence Collaboration Endpoint Software Command Injection VulnerabilityEPSS 0.5%CVE-2026-82369HIGHInsufficient input sanitization of shell metacharacters in Brocade SANnav before 3.0.1aEPSS 0.5%CVE-2022-35976MEDIUMImproper KubeConfig handling allows arbitrary code executionEPSS 0.5%CVE-2026-79535MEDIUMmbailey VoiceMode <= 8.10.1 is vulnerable to OS Command Injection. The update_config MCP tool (and the "voicemode config set" CLI) writes a EPSS 0.5%CVE-2024-41956HIGHSoft Serve allows arbitrary code execution by crafting git-lfs requestsEPSS 0.5%CVE-2023-41838MEDIUMAn improper neutralization of special elements used in an os command ('os command injection') in FortiManager 7.4.0 and 7.2.0 through 7.2.3 EPSS 0.5%CVE-2025-41281HIGHNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in WateEPSS 0.5%