Fallos del tipo CWE-77

2811 resultados

Injeção de comando via entrada não sanitizada

O software constrói comandos (shell, SQL, LDAP, etc.) usando dados de entrada do usuário sem neutralizar caracteres especiais que alteram a semântica do comando. Um atacante injeta metacaracteres (como `;`, `|`, `$()`) para executar instruções não previstas.

Ejemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validação. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos, porque o ponto-e-vírgula encadeia comandos no shell.

Cómo mitigar

Use APIs de execução que separam dados de comando (ex: `execvp()` com array de argumentos em vez de shell, prepared statements para SQL). Se shell for inevitável, whitelist rigoroso de entrada e escape apropriado com `escapeshellarg()` ou equivalente na linguagem.

CVE-2026-3959MEDIUM0xKoda WireMCP Tshark CLI index.js server.tool os command injectionEPSS 1.1%CVE-2026-5007MEDIUMkazuph mcp-docs-rag add_git_repository/add_text_file index.ts cloneRepository os command injectionEPSS 1.1%CVE-2026-19284MEDIUMMauricioMilano coder-api Projects Endpoint projects.ts createProject command injectionEPSS 1.1%CVE-2026-15669MEDIUMlouisho5 picobot exec Tool exec.go ExecTool.Execute os command injectionEPSS 1.1%CVE-2026-19329MEDIUMandreahaku codex_mcp ask MCP Tool codex-process-simple.ts command injectionEPSS 1.1%CVE-2026-19044MEDIUMLeeSinLiang godot-mcp create_scene/add_node index.ts executeOperation command injectionEPSS 1.1%CVE-2026-16628MEDIUMoclif JIT Plugin Entry child_process.exec os command injectionEPSS 1.1%CVE-2026-16489MEDIUMjsforce SFDX Connection Registry sfdx.js _execCommand os command injectionEPSS 1.1%CVE-2026-19332MEDIUMNellyW8 MCP4EDA run_openlane/view_waveform command injectionEPSS 1.1%CVE-2026-19333MEDIUMNightTrek Supabase-MCP generate_types command injectionEPSS 1.1%CVE-2026-81562MEDIUMAlexGladkov claude-in-mobile client.ts execSync os command injectionEPSS 1.1%CVE-2026-16631MEDIUMpublint package-manager pack.js child_process.exec os command injectionEPSS 1.1%CVE-2026-78430MEDIUMsworddut mcp-ffmpeg-helper Tool handlers.ts handleToolCall os command injectionEPSS 1.1%CVE-2026-5602MEDIUMNor2-io heim-mcp new_heim_application tools.ts registerTools os command injectionEPSS 1.1%CVE-2026-4198MEDIUMhypermodel-labs mcp-server-auto-commit index.ts getGitChanges command injectionEPSS 1.1%CVE-2026-19279MEDIUMMIMICLab mcp-pdf-vision index.ts load_pdf command injectionEPSS 1.1%CVE-2026-19045MEDIUMNocteDefensor LudusMCP get_credential_from_user secretDialog.ts SecretDialog.showSecretDialog command injectionEPSS 1.1%CVE-2022-20851MEDIUMCisco IOS XE Software Web UI Command Injection VulnerabilityEPSS 1.1%CVE-2024-25081MEDIUMSplinefont in FontForge through 20230101 allows command injection via crafted filenames.EPSS 1.1%CVE-2026-5023MEDIUMDeDeveloper23 codebase-mcp RepoMix codebase.ts saveCodebase os command injectionEPSS 1.1%