Weaknesses of type CWE-78

4,665 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2023-40357HIGHMultiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected products/versions are aEPSS 0.5%CVE-2025-20319MEDIUMRemote Command Execution through Scripted Input Files in Splunk EnterpriseEPSS 0.5%CVE-2026-13477MEDIUMIBM QRadar SIEM is vulnerable to remote code execution by privileged usersEPSS 0.5%CVE-2025-54941MEDIUMApache Airflow: Command injection in "example_dag_decorator"EPSS 0.5%CVE-2026-33310HIGHIntake has a Command Injection via shell() Expansion in Parameter DefaultsEPSS 0.5%CVE-2026-46399CRITICALAuthenticated Remote Code Execution via File OverwriteEPSS 0.5%CVE-2026-29783HIGHGitHub Copilot CLI allows for dangerous shell expansion patterns that enable arbitrary command executionEPSS 0.5%CVE-2026-46716CRITICALNezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cronEPSS 0.5%CVE-2026-19702HIGHOS Command Injection in TÜBİTAK BİLGEM's Pardus Boot RepairEPSS 0.5%CVE-2025-9997MEDIUMCWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause comEPSS 0.5%CVE-2024-22132HIGHCode Injection vulnerability in SAP IDES SystemsEPSS 0.5%CVE-2026-44932HIGHindirect remote shell command injection via unsanitized DHCP options in wickedEPSS 0.5%CVE-2026-71312HIGHrclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command ExecutionEPSS 0.5%CVE-2025-65074HIGHOS Command Injection via Path Traversal in WaveStore ServerEPSS 0.5%CVE-2025-70828HIGHAn issue in Datart v1.0.0-rc.3 allows attackers to execute arbitrary code via the url parameter in the JDBC configurationEPSS 0.5%CVE-2025-47782HIGHmotionEye vulnerable to RCE in add_camera Function Due to unsafe command executionEPSS 0.5%CVE-2024-42167CRITICALCommand Injection in OrganisationnameEPSS 0.5%CVE-2024-42166CRITICALCommand Injection in ApplicationnameEPSS 0.5%CVE-2026-26982MEDIUMGhostty affected by arbitrary command execution via control characters in paste and drag-and-drop operationsEPSS 0.5%CVE-2026-62371HIGHKubeEdge: Command Injection in NodeUpgradeJob - RCE on edge nodes via v1alpha2 APIEPSS 0.5%