Weaknesses of type CWE-78

4,668 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-68519HIGHGlances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)EPSS 0.2%CVE-2024-21782MEDIUMBIG-IP and BIG-IQ secure copy vulnerabilityEPSS 0.2%CVE-2023-53158MEDIUMThe gix-transport crate before 0.36.1 for Rust allows command execution via the "gix clone 'ssh://-oProxyCommand=open$IFS" substring. NOTE: EPSS 0.2%CVE-2026-34779MEDIUMElectron: AppleScript injection in app.moveToApplicationsFolder on macOSEPSS 0.2%CVE-2023-43066MEDIUM Dell Unity prior to 5.3 contains a Restricted Shell Bypass vulnerability. This could allow an authenticated, local attacker to exploit thisEPSS 0.2%CVE-2025-54595HIGHPearcleaner's unauthenticated access to privileged XPC helper allows root command executionEPSS 0.2%CVE-2025-20220MEDIUMA vulnerability in the CLI of Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure Firewall Threat Defense (FTD) SoftwareEPSS 0.2%CVE-2026-68939LOWPyenv: Glob/wildcard metacharacters bypass is_version_safe(), causing silent version/interpreter substitution via unquoted expansion (CVE-2022-35861 residual)EPSS 0.2%CVE-2026-68518HIGHGlances: Command injection bypass of action-template sanitizer via cross-field shell-operator reconstructionEPSS 0.2%CVE-2026-20040HIGHCisco IOS XR Software CLI Privilege Escalation VulnerabilityEPSS 0.2%CVE-2026-49219MEDIUMImageMagick: Policy Bypass can read disallowed filesEPSS 0.2%CVE-2026-10805MEDIUMNetworkmanager: networkmanager: local privilege escalation via malformed mud urls in dhclient backendEPSS 0.2%CVE-2026-87088HIGHTanium addressed an unauthorized code execution vulnerability in Enforce.EPSS 0.2%CVE-2025-20213MEDIUMCisco Catalyst SDWAN Manager Arbitrary File Overwrite VulnerabilityEPSS 0.2%CVE-2026-41010HIGHReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@release_dir, 'jobs', "#{name}.tgz") where EPSS 0.2%CVE-2026-90894HIGHParallels Desktop local privilege escalation via appliance extract argument injectionEPSS 0.2%CVE-2025-54314LOWThor before 1.4.0 can construct an unsafe shell command from library input. NOTE: this is disputed by the Supplier because "the method that EPSS 0.2%CVE-2025-6183HIGHConfigd InjectionEPSS 0.2%CVE-2026-67180HIGHGoogle Turbinia arbitrary command executionEPSS 0.2%CVE-2026-55448MEDIUMmise: Local credential_command executes untrusted configEPSS 0.2%