Weaknesses of type CWE-78

4,668 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-41421HIGHSiYuan Desktop Notification XSS Leads to Electron RCEEPSS 0.2%CVE-2026-62982HIGHGlances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injectionEPSS 0.2%CVE-2026-55580HIGHmcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode AllowlistEPSS 0.2%CVE-2026-22169HIGHOpenClaw < 2026.2.22 - Allowlist Bypass via sort Configuration in safeBinsEPSS 0.2%CVE-2025-12122MEDIUMPopup Box – Easily Create WordPress Popups <= 3.2.12 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.2%CVE-2023-20193MEDIUMA vulnerability in the Embedded Service Router (ESR) of Cisco ISE could allow an authenticated, local attacker to read, write, or delete arbEPSS 0.2%CVE-2026-10544MEDIUMImproper neutralization of special elements in the built-in PAM provider password rotation templates in Devolutions Server allows an authentEPSS 0.2%CVE-2026-78424HIGHOS Command Injection in Packet-Capture (Sniffer) Filter leading to Remote Code Execution on Kubernetes NodesEPSS 0.2%CVE-2026-17262MEDIUMIBM i is Affected By Denial of Service and Security Restriction Bypass Vulnerabilities in FTP [, ]EPSS 0.2%CVE-2026-84233HIGHRpm: command execution via macro expansion in `rpmuncompress -x` for crafted `.gem` filenamesEPSS 0.2%CVE-2026-75056HIGHIn JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possibleEPSS 0.2%CVE-2026-42290HIGHprotobufjs-cli: OS Command InjectionEPSS 0.2%CVE-2025-20308MEDIUMCisco Spaces Connector Privilege Escalation VulnerabilityEPSS 0.2%CVE-2026-44106HIGHLocal Privilege Escalation vulnerability in /etc/init.d/user-applications via customer website fileEPSS 0.2%CVE-2026-44099HIGHLocal Privilege Escalation via pppd password injectionEPSS 0.2%CVE-2026-44095HIGHLocal Privilege Escalation via Network scriptsEPSS 0.2%CVE-2026-48098HIGHNexTOR IP Changer Unsafely Uses sudo and shell=TrueEPSS 0.2%CVE-2026-44093HIGHLocal Privilege Escalation vulnerability in /etc/init.d/user-applications via user-application start scriptEPSS 0.2%CVE-2026-44096HIGHudhcpc Privilege EscalationEPSS 0.2%CVE-2026-16932HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.2%