Weaknesses of type CWE-78

4,665 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-44346HIGHBentoML: Dockerfile command injection via envs[*].name in bentofile.yamlEPSS 0.5%CVE-2026-44345HIGHBentoML: Dockerfile command injection via docker.base_imageEPSS 0.5%CVE-2026-62182HIGHKubeEdge: ConfigUpdateJob updateFields enables remote shell injection and code execution on edge nodesEPSS 0.5%CVE-2026-45035CRITICALTabby: RCE via `tabby://run` URL SchemeEPSS 0.5%CVE-2025-36607HIGHDell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nas utility. An authenticated attacker couEPSS 0.5%CVE-2025-36569MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 releasEPSS 0.5%CVE-2023-3313HIGH An OS common injection vulnerability exists in the ESM certificate API, whereby incorrectly neutralized special elements may have allowed aEPSS 0.5%CVE-2026-17248HIGHIBM i is Affected By Multiple Vulnerabilities in the Debug ServerEPSS 0.5%CVE-2026-44258CRITICALefw4.X: Path Traversal via Unchecked dst Parameter leads to Remote Code ExecutionEPSS 0.5%CVE-2025-54469CRITICALNeuVector Enforcer is vulnerable to Command Injection and Buffer overflowEPSS 0.5%CVE-2024-53992HIGHunzip-bot Allows Remote Code Execution (RCE) via archive extraction, password prompt, or video uploadEPSS 0.5%CVE-2023-31188HIGHMultiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected products/versions are aEPSS 0.5%CVE-2023-28617HIGHorg-babel-execute:latex in ob-latex.el in Org Mode through 9.6.1 for GNU Emacs allows attackers to execute arbitrary commands via a file namEPSS 0.5%CVE-2024-20469MEDIUMCisco Identity Services Engine Command Injection VulnerabilityEPSS 0.5%CVE-2024-11681MEDIUMRemote Code Execution in MacPortsEPSS 0.5%CVE-2023-43069HIGH Dell SmartFabric Storage Software v1.4 (and earlier) contain(s) an OS Command Injection Vulnerability in the CLI. An authenticated local atEPSS 0.5%CVE-2025-23344HIGHThe NVIDIA NVDebug tool contains a vulnerability that may allow an actor to run code on the platform host as a non-privileged user. A succesEPSS 0.5%CVE-2024-45325MEDIUMAn improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiDDoSEPSS 0.5%CVE-2026-41064CRITICALAVideo has an incomplete fix for CVE-2026-33502 (Command Injection)EPSS 0.5%CVE-2026-25044HIGHBudibase: Command Injection in Bash Automation StepEPSS 0.5%