Fallos del tipo CWE-78

4662 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2025-54415CRITICALdag-factory's CI/CD Workflow Allows for Repository Takeover and Secret ExfiltrationEPSS 0.7%CVE-2026-28460MEDIUMOpenClaw < 2026.2.22 - Allowlist Bypass via Shell Line-Continuation Command Substitution in system.runEPSS 0.7%CVE-2026-78569HIGHLangflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guardsEPSS 0.7%CVE-2026-9208HIGHTanium addressed an unauthorized code execution vulnerability in Connect.EPSS 0.7%CVE-2026-9207HIGHTanium addressed an unauthorized code execution vulnerability in Connect.EPSS 0.7%CVE-2026-27626CRITICALOliveTin vulnerable to OS Command Injection via `password` argument type and webhook JSON extraction bypasses shell safety checksEPSS 0.7%CVE-2026-34158HIGHCoolify: Command injection via single-quote breakout in Docker Compose custom commandsEPSS 0.7%CVE-2024-42370HIGHLitestar repository vulnerable to Environment Variable injection in `docs-preview.yml` workflowEPSS 0.7%CVE-2026-88277HIGHGV-LPCLPC2011/2211 - ONVIF Subscribe Address Command InjectionEPSS 0.7%CVE-2026-55897HIGHluci-app-advanced-reboot read ACL exposes /bin/sh through file.exec, allowing delegated users to run commands as rootEPSS 0.7%CVE-2026-73294CRITICALSemaphore U: OS Command InjectionEPSS 0.7%CVE-2026-42204HIGHCoolify: Authenticated RCE via SHELL_SAFE_COMMAND_PATTERN regression → host rootEPSS 0.7%CVE-2026-42153HIGHCoolify: PostgreSQL Healthcheck Command Injection Allows Root Code Execution in ContainerEPSS 0.7%CVE-2026-34058HIGHCoolify: OS Command Injection via Unmanaged Container Operations - Remote Code ExecutionEPSS 0.7%CVE-2026-72869CRITICALDokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCEEPSS 0.7%CVE-2026-72872CRITICALDokploy: OS Command Injection via Bitbucket `owner`/`repository` in `git clone`EPSS 0.7%CVE-2026-73263CRITICALProwler: RCE on Prowler App workers via kubeconfig auth-provider cmd-pathEPSS 0.7%CVE-2026-82412HIGHntopng: Remote Code Execution via OS Command Injection in Vulnerability-Scan REST APIEPSS 0.7%CVE-2026-72865CRITICALDokploy: OS Command Injection via compose `composePath`EPSS 0.7%CVE-2024-36491CRITICALFutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allow an administrative user to execute an arbitrary OEPSS 0.7%