Fallos del tipo CWE-78

4664 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2025-24379HIGHDell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InjectionEPSS 0.6%CVE-2025-24378HIGHDell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InjectionEPSS 0.6%CVE-2023-25554HIGH A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that allows aEPSS 0.6%CVE-2026-27849CRITICALMissing neutralization in Linksys MR9600, Linksys MX4200EPSS 0.6%CVE-2026-27848CRITICALMissing neutralization in Linksys MR9600, Linksys MX4200EPSS 0.6%CVE-2025-43920MEDIUMGNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to executeEPSS 0.6%CVE-2026-44723MEDIUMVowpal Wabbit: Shell injection via crafted PR title in python_checks.yml allows arbitrary command execution on CI runnerEPSS 0.6%CVE-2022-35717HIGH"IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending EPSS 0.6%CVE-2023-24422HIGHA sandbox bypass vulnerability involving map constructors in Jenkins Script Security Plugin 1228.vd93135a_2fb_25 and earlier allows attackerEPSS 0.6%CVE-2025-30370HIGHjupyterlab-git has a command injection vulnerability in "Open Git Repository in Terminal"EPSS 0.6%CVE-2026-72877CRITICALDokploy: Command Injection via dockerImage in buildRemoteDockerEPSS 0.6%CVE-2026-68560HIGHWekan:hell Injection in External Antivirus Scanner Path via asyncExecEPSS 0.6%CVE-2026-65590MEDIUMn8n before 2.30.1 Shell Sandbox Bypass on Linux WindowsEPSS 0.6%CVE-2024-49563HIGHDell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InjectionEPSS 0.6%CVE-2026-22621HIGHImproper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticatedEPSS 0.6%CVE-2026-89139HIGHTemporal Server worker deployment compute provider executes a caller-supplied command on the Worker Service hostEPSS 0.6%CVE-2025-10622HIGHForeman: os command injection via ct_location and fcct_location parametersEPSS 0.6%CVE-2026-77601HIGHOpenC3 COSMOS: Authenticated OS command injection via the `pypi_url` settingEPSS 0.6%CVE-2026-100368HIGHCliInvoke.Specializations: Command injection in PowerShell and Cmd shell wrappersEPSS 0.6%CVE-2026-95521HIGHRpm: rpm: shell command injection via macro expansion of source/spec file basenames when installing a source rpmEPSS 0.6%