Fallos del tipo CWE-78

4653 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2021-42852HIGHA command injection vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an authenticated user to execuEPSS 0.8%CVE-2026-1665MEDIUMCommand Injection in nvm via NVM_AUTH_HEADER in wget code pathEPSS 0.8%CVE-2026-49255HIGHelecterm: Command Injection in File System Operations (rmrf, mv, cp)EPSS 0.8%CVE-2026-45558CRITICALRoxy-WI: Authenticated RCE on every managed HAProxy load balancer via `option` field config injection in section saveEPSS 0.8%CVE-2021-26115HIGHAn OS command injection (CWE-78) vulnerability in FortiWAN version 4.5.7 and below Command Line Interface may allow a local, authenticated aEPSS 0.8%CVE-2024-46330HIGHVONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the iptablesWebsFilterRun object.EPSS 0.8%CVE-2017-6707—A vulnerability in the CLI command-parsing code of the Cisco StarOS operating system for Cisco ASR 5000 Series 11.0 through 21.0, 5500 SerieEPSS 0.8%CVE-2024-56137MEDIUMMaxKB RCE vulnerability in function libraryEPSS 0.8%CVE-2026-42143HIGHCoolify: OS Command Injection via Persistent Volume Names - Root RCE on Managed ServersEPSS 0.8%CVE-2026-72738CRITICALDokploy: Authenticated RCE via Command Injection in backup.listBackupFiles search ParameterEPSS 0.8%CVE-2026-72740CRITICALDokploy: OS Command Injection via SSH-form `customGitUrl` domain in `ssh-keyscan`EPSS 0.8%CVE-2026-0980HIGHRubyipmi: red hat satellite: remote code execution in rubyipmi via malicious bmc usernameEPSS 0.8%CVE-2026-26899HIGHAn issue was discovered in luci-app-https-dns-proxy on OpenWrt PR #15 (< 2026-01-17). The setInitAction function in /usr/libexec/rpcd/luci.hEPSS 0.8%CVE-2024-38889CRITICALAn issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker tEPSS 0.8%CVE-2026-34168HIGHCoolify: Command injection via unsanitized persistent storage name in docker volume commandsEPSS 0.8%CVE-2026-52891CRITICALWekan: Shell Injection via Avatar UploadEPSS 0.8%CVE-2026-34153HIGHCoolify LocalFileVolume fs_path command injection enables RCEEPSS 0.8%CVE-2026-34034HIGHCoolify: Host RCE via Sentinel token injectionEPSS 0.8%CVE-2026-3014MEDIUMRemote Code Execution by administrative user on the Management ServerEPSS 0.8%CVE-2024-41585MEDIUMDrayTek Vigor3910 devices through 4.3.2.6 are affected by an OS command injection vulnerability that allows an attacker to leverage the recvEPSS 0.8%