Fallos del tipo CWE-78

4662 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2026-34152HIGHCoolify: Command Injection via Newline in Pre/Post Deployment Commands (Heredoc Transport)EPSS 0.7%CVE-2024-31162HIGHASUS Download Master - OS Command InjectionEPSS 0.6%CVE-2026-56686HIGHDell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InEPSS 0.6%CVE-2025-22366HIGHMennekes smart/premium charges systems, Command injection in firmware upgradeEPSS 0.6%CVE-2025-25039MEDIUMAuthenticated Remote Command Injection in HPE Aruba Networking ClearPass Policy Manager Web-Based Management InterfaceEPSS 0.6%CVE-2025-22367HIGHMennekes smart/premium charges systems, Command injection in time settingEPSS 0.6%CVE-2025-22368HIGHMennekes smart/premium charges systems, Command injection in sCU firmware updateEPSS 0.6%CVE-2026-59910HIGHDell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InEPSS 0.6%CVE-2025-41663CRITICALWeidmueller: Security routers IE-SR-2TX are affected by Command InjectionEPSS 0.6%CVE-2025-65882CRITICALAn issue was discovered in openmptcprouter thru 0.64 in file common/package/utils/sys-upgrade-helper/src/tools/sysupgrade.c in function creaEPSS 0.6%CVE-2026-67324CRITICALGitPython 3.1.50 Authentication Bypass via Joined Short OptionsEPSS 0.6%CVE-2024-22228HIGH Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cifssupport utility. An authenticated attackerEPSS 0.6%CVE-2024-24431HIGHA reachable assertion in the ogs_nas_emm_decode function of Open5GS v2.7.0 allows attackers to cause a Denial of Service (DoS) via a craftedEPSS 0.6%CVE-2024-22227HIGH Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_dc utility. An authenticated attacker could poEPSS 0.6%CVE-2023-49691HIGHA vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.0), RUGGEDCOM RM1224 LTE(4G) NAM EPSS 0.6%CVE-2025-37126HIGHAuthenticated Remote Code Execution in HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line InterfaceEPSS 0.6%CVE-2026-100844HIGHMONAI before 1.6.0 OS Command Injection via dataset_name_or_idEPSS 0.6%CVE-2026-73662HIGHAuthenticated FreePBX Music RCE via mpg123 and Asterisk Call FilesEPSS 0.6%CVE-2025-52573MEDIUMCommand Injection in MCP Server ios-simulator-mcpEPSS 0.6%CVE-2025-12744HIGHAbrt: command-injection in abrt leading to local privilege escalationEPSS 0.6%