Weaknesses of type CWE-78

4,668 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-9560CRITICALPrivilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands wEPSS 0.4%CVE-2026-30309HIGHInfCode's terminal auto-execution module contains a critical command filtering vulnerability that renders its blacklist security mechanism cEPSS 0.4%CVE-2026-25621HIGHArista Edge Threat Management NGFW Reports Application Insecure Input ValidationEPSS 0.4%CVE-2023-20082MEDIUMCisco IOS XE Software for Cisco Catalyst 9300 Series Switches Secure Boot Bypass VulnerabilityEPSS 0.4%CVE-2026-31999MEDIUMOpenClaw 2026.2.26 < 2026.3.1 - Current Working Directory Injection via Windows Wrapper Resolution FallbackEPSS 0.4%CVE-2021-1452MEDIUMCisco IOS XE ROM Monitor Software for Cisco Industrial Switches OS Command Injection VulnerabilityEPSS 0.4%CVE-2026-15816HIGHDracut: dracut: root code execution via unescaped error message written to sourced emergency hook script in die()EPSS 0.4%CVE-2026-17420MEDIUMIBM i is Affected By Multiple Vulnerabilities in SQLEPSS 0.4%CVE-2025-64106HIGHCursor: Speedbump Modal Bypass in MCP Server Deep-LinkEPSS 0.4%CVE-2019-1725MEDIUMCisco UCS B-Series Blade Servers Local Management CLI Arbitrary File Creation or CLI Parameter Injection VulnerabilityEPSS 0.4%CVE-2025-54133MEDIUMCursor's MCP Install Deeplink Does Not Show Arguments in its User-DialogEPSS 0.4%CVE-2026-86035HIGHWeblate: Mercurial argument injection via repository filenames allows authenticated command executionEPSS 0.4%CVE-2023-23693MEDIUM Dell VxRail, versions prior to 7.0.450, contains an OS command injection Vulnerability in DCManager command-line utility. A local high privEPSS 0.4%CVE-2025-64091HIGHAuthenticated Remote Code Execution in the NTP-configurationEPSS 0.4%CVE-2026-54344MEDIUMToolJet GitHub Actions comment body shell injection exposes deployment secretsEPSS 0.4%CVE-2026-23882HIGHBlinko: Admin RCE - MCP Server Command InjectionEPSS 0.4%CVE-2025-20349MEDIUMCisco DNA Center API Command Injection VulnerabilityEPSS 0.4%CVE-2024-38471MEDIUMMultiple TP-LINK products allow a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by restoring aEPSS 0.4%CVE-2025-53637MEDIUMMeshtastic allows Command Injection in GitHub ActionEPSS 0.4%CVE-2026-86530HIGHBUFFALO Wi-Fi products handle some web form input improperly to assemble command line strings internally. An administrative user may send a EPSS 0.4%