Weaknesses of type CWE-78

4,669 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-42148LOWCoolify: Command Injection via Unescaped Version String in Docker BuildEPSS 0.2%CVE-2026-41011HIGHPackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz") and name = package_EPSS 0.2%CVE-2025-6181HIGHThe StrongDM Windows service incorrectly handled input validation. Authenticated attackers could potentially exploit this leading to privileEPSS 0.2%CVE-2026-102925HIGHvirtualenv bash and fish activation scripts execute commands embedded in pathsEPSS 0.2%CVE-2026-104859HIGHNx: OS command injection in the @nx/docker release pipelineEPSS 0.1%CVE-2026-17133HIGHIBM App Connect Enterprise Toolkit is vulnerable to arbitrary code execution due to multiple CVEsEPSS 0.1%CVE-2026-101032HIGHnavi through 2.24.0 OS Command Injection via Cheatsheet VariablesEPSS 0.1%CVE-2026-95519HIGHRpm: code execution via macro expansion of manifest entries in `rpmgi` (`-q -p` / verify manifest flows)EPSS 0.1%CVE-2026-79992HIGHEmacs: emacs: command injection via crafted filenames in trampEPSS 0.1%CVE-2026-73077HIGHVim: Arbitrary Code Execution via Shell Keyword LookupEPSS 0.1%CVE-2026-102937HIGHvirtualenv: Command injection via --prompt in activate.bat (batch activator)EPSS 0.1%CVE-2026-77585MEDIUMImproper Validation of SSH Target in Okta Privileged Access ClientEPSS 0.1%CVE-2026-102120HIGHKiteworks Core OS Command InjectionEPSS 0.1%CVE-2026-19515HIGHOS Command Injection via Unit Test Execution in WSO2 Integrator MI VS Code Extension Allows Arbitrary Command ExecutionEPSS 0.1%CVE-2026-20008MEDIUMCisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Lua Code Injection VulnerabilityEPSS 0.1%CVE-2026-85288MEDIUMNotepad++: Shortcuts.xml macro HMAC bypass still reachable via the "Run a Macro Multiple Times" dialogEPSS 0.1%CVE-2026-91837HIGHNetworkmanager-iodine: networkmanager-iodine: local privilege escalation to root via nameserver option injectionEPSS 0.1%CVE-2026-16826MEDIUMIBM i is Affected By Multiple Vulnerabilities in Debug ServerEPSS 0.1%CVE-2026-85082HIGHMaple Media Root Browser Classic 3.3.0 - OS command injection through crafted SQLite filenamesEPSS 0.1%CVE-2026-17499MEDIUMIBM i is Affected By Multiple Vulnerabilities in Debug ServerEPSS 0.1%