Fallos del tipo CWE-78

4664 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2026-24887HIGHClaude Code has a Command Injection in find Command Bypasses User Approval PromptEPSS 0.6%CVE-2026-44055HIGHBitwise OR logic bug enables shell injectionEPSS 0.6%CVE-2025-62713HIGHKottster app reinitialization can be re-triggered allowing command injection in development modeEPSS 0.6%CVE-2025-60803CRITICALAntabot White-Jotter up to commit 9bcadc was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the compEPSS 0.6%CVE-2026-86108HIGHSecurity Advisory 0181EPSS 0.6%CVE-2022-4515HIGHA flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename spEPSS 0.6%CVE-2024-32118MEDIUMMultiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet ForEPSS 0.6%CVE-2026-72884HIGHDokploy: Command Injection via Compose Custom CommandEPSS 0.6%CVE-2026-93012CRITICALEmail::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command execution on Windows sending a message whose envelope address reaches the shell in _sendmail_pipeEPSS 0.6%CVE-2026-55673HIGHPowSyBl: Command Injection in LocalCommandExecutor-sEPSS 0.6%CVE-2026-55420HIGHDiscourse: Remote code execution via pdf uploadsEPSS 0.6%CVE-2022-43948MEDIUMA improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 7.0.0 through 7.0.EPSS 0.6%CVE-2022-42433MEDIUMThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR841N TL-WR841N(US)_EPSS 0.6%CVE-2026-13336HIGHCWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause exeEPSS 0.6%CVE-2026-54674HIGHAuthenticated Command Injection in FreePBX UCP InterfaceEPSS 0.6%CVE-2018-25143HIGHMicrohard Systems IPn4G 1.1.0 Backdoor Jailbreak via Microhard Sh ServiceEPSS 0.6%CVE-2023-44277HIGH Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in EPSS 0.6%CVE-2024-56808LOWMedia Streaming add-onEPSS 0.6%CVE-2026-64625CRITICALAVideo before 29.0 OS Command Injection via execAsyncEPSS 0.6%CVE-2024-58286CRITICALdizqueTV 1.5.3 Remote Code Execution via FFMPEG Executable PathEPSS 0.6%