Fallos del tipo CWE-78

4628 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2026-8665HIGHOS Command Injection in Rapid7 InsightConnect Translate PluginEPSS 1.2%CVE-2026-80138CRITICALClipBucket V5 5.5.1 through 5.5.3-#153 OS Command Injection via Installer php_cli_filepath ParameterEPSS 1.2%CVE-2026-19978MEDIUMjiantao88 android-mcp-server Command Execution index.js child_process.exec os command injectionEPSS 1.2%CVE-2026-0855HIGHMerit LILIN|IP Camera - OS Command InjectionEPSS 1.2%CVE-2023-47220MEDIUMMedia Streaming add-onEPSS 1.2%CVE-2026-24506HIGHDell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13EPSS 1.2%CVE-2026-4802HIGHCockpit: cockpit: arbitrary command execution via crafted links in system logs uiEPSS 1.2%CVE-2023-26128HIGHAll versions of the package keep-module-latest are vulnerable to Command Injection due to missing input sanitization or other checks and sanEPSS 1.2%CVE-2012-10037CRITICALPhpTax pfilez Parameter Exec Remote Code InjectionEPSS 1.2%CVE-2023-50198HIGHD-Link G416 cfgsave Command Injection Remote Code Execution VulnerabilityEPSS 1.2%CVE-2026-40030HIGHparseusbs < 1.9 Command Injection via Volume Path ArgumentEPSS 1.2%CVE-2019-1627MEDIUMCisco Integrated Management Controller Information Disclosure VulnerabilityEPSS 1.2%CVE-2023-51217HIGHAn issue discovered in TenghuTOS TWS-200 firmware version:V4.0-201809201424 allows a remote attacker to execute arbitrary code via crafted cEPSS 1.2%CVE-2025-63705HIGHNPM package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js.EPSS 1.2%CVE-2026-40032HIGHUAC < 3.3.0-rc1 Command Injection via Placeholder SubstitutionEPSS 1.2%CVE-2023-52311CRITICALCommand injection in _wget_downloadEPSS 1.2%CVE-2023-52310CRITICALCommand injection in get_online_pass_intervalEPSS 1.2%CVE-2023-52314CRITICALCommand injection in convert_shape_compareEPSS 1.2%CVE-2026-23816HIGHAuthenticated Command Injection found in admin AOS-CX CLI commandEPSS 1.2%CVE-2024-39686CRITICALfishaudio/Bert-VITS2 Command Injection in webui_preprocess.py bert_gen functionEPSS 1.2%