Weaknesses of type CWE-78

4,665 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-49492HIGHMarkdown Preview Enhanced OS Command Injection in External File and Link OpeningEPSS 0.5%CVE-2022-41751HIGHJhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 oEPSS 0.5%CVE-2026-55427HIGHCoder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`EPSS 0.5%CVE-2024-40895MEDIUMFFRI AMC versions 3.4.0 to 3.5.3 and some OEM products that implement/bundle FFRI AMC versions 3.4.0 to 3.5.3 allow a remote unauthenticatedEPSS 0.5%CVE-2022-35849HIGHAn improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiADC 7.1.0 thEPSS 0.5%CVE-2025-36606HIGHDell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nfssupport utility. An authenticated attacEPSS 0.5%CVE-2025-43943MEDIUMDell Cloud Disaster Recovery, version(s) prior to 19.20, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OEPSS 0.5%CVE-2025-69755HIGHAn issue in Neterbit NW-431F Router vNW-431F-20241014-IR03 allows a remote attacker to obtain sensitive information and execute arbitrary coEPSS 0.5%CVE-2026-75363MEDIUMAn issue in Comfast CF-WR630AX v.2.7.0.2 allows a remote attacker to execute arbitrary code via the /usr/bin/webmgnt, /cgi-bin/mbox-config, EPSS 0.5%CVE-2019-1775MEDIUMCisco NX-OS Software Command Injection VulnerabilityEPSS 0.5%CVE-2023-48668HIGH Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 on DDMC contain an OS command injection vulnerabiEPSS 0.5%CVE-2019-1774MEDIUMCisco NX-OS Software Command Injection VulnerabilityEPSS 0.5%CVE-2021-35031MEDIUMA vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware, which could allow EPSS 0.5%CVE-2026-91936HIGHFlowise before 3.1.4 Script Injection via Docker WorkflowsEPSS 0.5%CVE-2026-70335HIGHGitHub Copilot and Visual Studio Code Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2019-12709MEDIUMCisco IOS XR Software for Cisco ASR 9000 VMAN CLI Privilege Escalation VulnerabilityEPSS 0.5%CVE-2025-43884HIGHDell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Improper Neutralization of Special Elements used in an OS EPSS 0.5%CVE-2025-52988HIGHJunos OS and Junos OS Evolved: Privilege escalation to root via CLI command 'request system logout'EPSS 0.5%CVE-2026-39382CRITICALdbt has a Command Injection in Reusable Workflow via Unsanitized comment-body OutputEPSS 0.5%CVE-2026-72904CRITICALFirecrawl: Arbitrary file read via JSON Schema $ref expansionEPSS 0.5%