Weaknesses of type CWE-78

4,668 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-43991HIGHJunoClaw: plugin-shell shell-injection bypass via substring blocklistEPSS 0.3%CVE-2026-44465HIGHZed: Zed IDE Arbitrary Code Execution via untrusted repository with poisoned .git/configEPSS 0.3%CVE-2023-20056MEDIUMCisco Access Point Software Denial of Service VulnerabilityEPSS 0.3%CVE-2026-24154HIGHNVIDIA Jetson Linux has vulnerability in initrd, where an unprivileged attacker with physical access coul inject incorrect command line arguEPSS 0.3%CVE-2024-54012HIGHCommand InjectionEPSS 0.3%CVE-2026-28463HIGHOpenClaw < 2026.2.14 - Arbitrary File Read via Shell Expansion in Safe Bins AllowlistEPSS 0.3%CVE-2025-43020MEDIUMPoly Clariti Manager - Multiple Security VulnerabilitiesEPSS 0.3%CVE-2026-57282MEDIUMJenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded into a generated SSH EPSS 0.3%CVE-2026-46709HIGHTabby: Drag-and-drop path injection still allows RCE via shell command substitution (incomplete fix for CVE-2026-45038)EPSS 0.3%CVE-2026-48703HIGHWarp: Command Injection via Warp code search tool argumentsEPSS 0.3%CVE-2023-20050MEDIUMCisco NX-OS Software CLI Command Injection VulnerabilityEPSS 0.3%CVE-2024-39521HIGHJunos OS Evolved: CLI parameter processing issue allows privilege escalationEPSS 0.3%CVE-2024-39523HIGHJunos OS Evolved: CLI parameter processing issue allows privilege escalationEPSS 0.3%CVE-2024-39524HIGHJunos OS Evolved: CLI parameter processing issue allows privilege escalationEPSS 0.3%CVE-2024-39522HIGHJunos OS Evolved: CLI parameter processing issue allows privilege escalationEPSS 0.3%CVE-2024-39520HIGHJunos OS Evolved: CLI parameter processing issue allows privilege escalationEPSS 0.3%CVE-2026-44461HIGHZed: Remote Command Injection via Unquoted Environment Variable Keys (SSH / WSL Remote)EPSS 0.2%CVE-2026-100559HIGHOpenClaw before 2026.8.1 Command Injection via Escaped NewlinesEPSS 0.2%CVE-2025-27079MEDIUMArbitrary File Creation vulnerability allows for Authenticated Remote Code Execution in CLI InterfaceEPSS 0.2%CVE-2023-40716MEDIUMAn improper neutralization of special elements used in an OS command vulnerability [CWE-78]  in the command line interpreter of FortiTester EPSS 0.2%