Weaknesses of type CWE-78

4,668 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2025-12737HIGHArbitrary Code Execution via Administrative Operations in Multiple WSO2 Products Allows Remote Code ExecutionEPSS 0.2%CVE-2026-0383HIGHInformation disclosure in Brocade Fabric OS before 9.2.1c2, 9.2.2 through 9.2.2a and 10.0.0EPSS 0.2%CVE-2023-20015MEDIUMCisco Firepower 4100 Series, Firepower 9300 Security Appliances, and UCS Fabric Interconnects Command Injection VulnerabilityEPSS 0.2%CVE-2026-85013HIGHEnvironment-modules: command injection in environment-modules bash completion via malicious module names containing shell metacharactersEPSS 0.2%CVE-2026-71551HIGHSuper Productivity: Arbitrary OS Command Execution via IPC EXEC Handler with Persistent WhitelistEPSS 0.2%CVE-2026-43990HIGHJunoClaw: plugin-shell shell-metacharacter injection via shell wrapperEPSS 0.2%CVE-2026-78630MEDIUMImproper Input Neutralization in Okta Access Gateway SNMP Configuration ProcessingEPSS 0.2%CVE-2021-41228HIGHCode injection in `saved_model_cli`EPSS 0.2%CVE-2026-16875HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.2%CVE-2025-37129MEDIUMAuthenticated Remote Code Execution allows Exploit in Scripts FeatureEPSS 0.2%CVE-2026-45136HIGHclaude-code-cache-fix: Local code execution via Python triple-quote injection in tools/quota-statusline.shEPSS 0.2%CVE-2026-31996LOWOpenClaw < 2026.2.19 - safeBins stdin-only bypass via sort output and recursive grep flagsEPSS 0.2%CVE-2026-57586HIGHCodeRAG: Gradle Wrapper Execution During Dependency Discovery Enables Arbitrary Code ExecutionEPSS 0.2%CVE-2026-25933MEDIUMArduino App Lab has Improper Data Validation in Internal Terminal InterfaceEPSS 0.2%CVE-2025-58374HIGHRoo Code: Auto-approve allows npm install execution of malicious postinstall scriptsEPSS 0.2%CVE-2026-14881HIGHCompass connection import allows to override OIDC browser open command (usually set through settings), allowing for arbitrary shell commands execution when connecting to cluster using OIDC auth flowEPSS 0.2%CVE-2025-67640MEDIUMJenkins Git client Plugin 6.4.0 and earlier does not not correctly escape the path to the workspace directory as part of an argument in a teEPSS 0.2%CVE-2021-35032MEDIUMA vulnerability in the 'libsal.so' of the Zyxel GS1900 series firmware version 2.60 could allow an authenticated local user to execute arbitEPSS 0.2%CVE-2026-46606HIGHGlances: Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vms/engines/virsh.pyEPSS 0.2%CVE-2024-20398HIGHCisco IOS XR Software Local Privilege Escalation VulnerabilityEPSS 0.2%