Weaknesses of type CWE-78

4,665 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-44666CRITICALHRConvert2: Missing Sanitization enables Unauthenticated Remote Command ExecutionEPSS 0.5%CVE-2026-55576HIGHMaaAssistantArknights: PR-title expression injection in release-preparation.ymlEPSS 0.5%CVE-2023-34873HIGHOn MOBOTIX P3 cameras before MX-V4.7.2.18 and Mx6 cameras before MX-V5.2.0.61, the tcpdump feature does not properly validate input, which aEPSS 0.5%CVE-2026-55748MEDIUMOpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharaEPSS 0.5%CVE-2026-102826HIGHsimple-git allows command execution through unblocked Git configuration includesEPSS 0.5%CVE-2025-70082MEDIUMLantronix EDS3000PS Unverified Password ChangeEPSS 0.5%CVE-2025-15559CRITICALUnauthenticated OS Command Injection in NesterSoft WorkTimeEPSS 0.5%CVE-2020-1734HIGHA flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() wiEPSS 0.5%CVE-2022-22298MEDIUMA improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiIsolator version 1.0.0, FortiIEPSS 0.5%CVE-2026-22902MEDIUMQuNetSwitchEPSS 0.5%CVE-2026-55581HIGHmcp-shell: Secure Mode Allowlist Bypass via Default `/bin/bash` ExecutableEPSS 0.5%CVE-2026-31854HIGHCursor Affected by Arbitrary Code Execution via Prompt Injection and Whitelist BypassEPSS 0.5%CVE-2024-48891MEDIUMAn Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR 7.6.0 throEPSS 0.5%CVE-2022-34437MEDIUMDell PowerScale OneFS, versions 8.2.2-9.3.0, contain an OS command injection vulnerability. A privileged local malicious user could potentiaEPSS 0.5%CVE-2026-20036MEDIUMCisco UCS Manager Software Command Injection VulnerabilityEPSS 0.5%CVE-2026-45632CRITICALDokploy: Schedule Authorization Bypass Enables Host/Server Command ExecutionEPSS 0.5%CVE-2025-27759MEDIUMAn improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiWeb veEPSS 0.4%CVE-2024-5461HIGHCommand or parameter injection via unique embedded switch SNMP commands.EPSS 0.4%CVE-2019-1770MEDIUMCisco NX-OS Software Command Injection VulnerabilityEPSS 0.4%CVE-2023-20023MEDIUMCisco Identity Services Engine Privilege Escalation VulnerabilitiesEPSS 0.4%