Fallos del tipo CWE-77
2831 resultadosInjeção de comando via entrada não sanitizada
O software constrói comandos (shell, SQL, LDAP, etc.) usando dados de entrada do usuário sem neutralizar caracteres especiais que alteram a semântica do comando. Um atacante injeta metacaracteres (como `;`, `|`, `$()`) para executar instruções não previstas.
Ejemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validação. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos, porque o ponto-e-vírgula encadeia comandos no shell.
Cómo mitigar
Use APIs de execução que separam dados de comando (ex: `execvp()` com array de argumentos em vez de shell, prepared statements para SQL). Se shell for inevitável, whitelist rigoroso de entrada e escape apropriado com `escapeshellarg()` ou equivalente na linguagem.
CVE-2025-70296MEDIUMA stored HTML injection vulnerability in the Recipe Notes rendering component in Mealie 3.3.1 allows remote authenticated users to inject arEPSS 0.2%CVE-2025-25791MEDIUMAn arbitrary file upload vulnerability in the plugin installation feature of YZNCMS v2.0.1 allows attackers to execute arbitrary code via upEPSS 0.2%CVE-2024-8402LOWImproper Neutralization of Special Elements used in a Command ('Command Injection') in GitLabEPSS 0.2%CVE-2026-46508HIGHTurborepo: VSCode Extension command injectionEPSS 0.2%CVE-2023-20097MEDIUMCisco Access Point Software Command Injection VulnerabilityEPSS 0.2%CVE-2026-34259HIGHOS Command Injection Vulnerability in SAP Forecasting & ReplenishmentEPSS 0.2%CVE-2023-33806HIGHInsecure default configurations in Hikvision Interactive Tablet DS-D5B86RB/B V2.3.0 build220119, allows attackers to execute arbitrary commaEPSS 0.2%CVE-2024-27763MEDIUMXPixelGroup BasicSR through 1.4.2 might locally allow code execution in contrived situations where "scontrol show hostname" is executed in tEPSS 0.2%CVE-2026-27001HIGHOpenClaw: Unsanitized CWD path injection into LLM promptsEPSS 0.2%CVE-2026-76339MEDIUMSPL Injection through the geostats Command in Splunk EnterpriseEPSS 0.2%CVE-2025-52687LOWJavaScript Injection Vulnerability in the OmniAccess Stellar Web Management InterfaceEPSS 0.2%CVE-2025-6522MEDIUMTrendMakers Sight Bulb Pro Command InjectionEPSS 0.2%CVE-2026-43990HIGHJunoClaw: plugin-shell shell-metacharacter injection via shell wrapperEPSS 0.2%CVE-2025-26237HIGHD-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution vulnerability in the flag parameter of msp_info, which can be exploited to run aEPSS 0.2%CVE-2023-40396HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17. AnEPSS 0.2%CVE-2023-36642MEDIUMAn improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiTester 3.0.0EPSS 0.2%CVE-2026-20169MEDIUMCisco IoT Field Network Director Command Injection VulnerabilityEPSS 0.2%CVE-2024-57695HIGHAn issue in Agnitum Outpost Security Suite 7.5.3 (3942.608.1810) and 7.6 (3984.693.1842) allows a local attacker to execute arbitrary code vEPSS 0.2%CVE-2026-57453MEDIUMVim: PowerShell Command Injection via Unescaped Filename in zip.vim ExtractionEPSS 0.2%CVE-2026-72913HIGHKitty: Command injection into the child shell via chained @kitty-echo + @kitty-ssh DCS escape sequencesEPSS 0.2%