Fallos del tipo CWE-78

4640 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2026-78430MEDIUMsworddut mcp-ffmpeg-helper Tool handlers.ts handleToolCall os command injectionEPSS 1.1%CVE-2026-5603MEDIUMelgentos magento2-dev-mcp index.ts executeMagerun2Command os command injectionEPSS 1.1%CVE-2026-15193MEDIUMAidanPark openclaw-android Android WebView Bridge JsBridge.kt os command injectionEPSS 1.1%CVE-2026-5007MEDIUMkazuph mcp-docs-rag add_git_repository/add_text_file index.ts cloneRepository os command injectionEPSS 1.1%CVE-2026-16735MEDIUMrelease-it conventional-changelog Changelog File index.js writeChangelog os command injectionEPSS 1.1%CVE-2026-16489MEDIUMjsforce SFDX Connection Registry sfdx.js _execCommand os command injectionEPSS 1.1%CVE-2024-42747HIGHIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWanIeCfg. AutEPSS 1.1%CVE-2026-25855HIGHOpenBullet2 0.3.2 Authenticated RCE via FileProxySource Script UploadEPSS 1.1%CVE-2026-15895HIGHOS command injection in jsii-diff in AWS jsiiEPSS 1.1%CVE-2026-85656HIGHOS command injection in Amazon log4j-cve-2021-44228-hotpatchEPSS 1.1%CVE-2026-49819CRITICALUpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wake_cmdEPSS 1.1%CVE-2026-5023MEDIUMDeDeveloper23 codebase-mcp RepoMix codebase.ts saveCodebase os command injectionEPSS 1.1%CVE-2025-13942CRITICALA command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C0 could allow a remoEPSS 1.1%CVE-2022-1410HIGHRemote Code Execution in Device42 ApplianceManager consoleEPSS 1.1%CVE-2022-25853HIGHAll versions of the package semver-tags are vulnerable to Command Injection via the getGitTagsRemote function due to improper input sanitizaEPSS 1.1%CVE-2019-1878HIGHCisco TelePresence Endpoint Command Shell Injection VulnerabilityEPSS 1.1%CVE-2024-51450CRITICALIBM Security Verify Directory Command ExecutionEPSS 1.1%CVE-2025-60017HIGHUnitree Go2, G1, H1, and B2 devices through 2025-09-20 allow root OS command injection via the hostapd_restart.sh wifi_ssid or wifi_pass parEPSS 1.1%CVE-2022-42279HIGHNVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to codEPSS 1.1%CVE-2022-48472CRITICALA Huawei printer has a system command injection vulnerability. Successful exploitation could lead to remote code execution. Affected productEPSS 1.1%