Fallos del tipo CWE-78

4664 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2025-9996MEDIUMCWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause theEPSS 0.5%CVE-2026-24129HIGHRuntipi is Vulnerable to Authenticated Arbitrary Remote Code ExecutionEPSS 0.5%CVE-2024-2421CRITICALLenelS2 NetBox Improper Neutralization of Special ElementsEPSS 0.5%CVE-2024-31668CRITICALrizin before v0.6.3 is vulnerable to Improper Neutralization of Special Elements via meta_set function in librz/analysis/meta.EPSS 0.5%CVE-2025-22605HIGHCoolify OS Command Injection Vulnerability in SSH Command GenerationEPSS 0.5%CVE-2026-71243HIGHbackmeup (npm) - OS Command Injection via Backup Option ValuesEPSS 0.5%CVE-2026-52483HIGHThe ping diagnostics and other similar functions of the MitraStar GPT-2741GNAC-N2-SV router with firmware BR_g8.10_1.11(WVK.0)b46 allow authEPSS 0.5%CVE-2026-45564HIGHRoxy-WI: Authenticated RCE via 'configver' URL parameter (os.system sink in /config/versions/.../save)EPSS 0.5%CVE-2026-72882CRITICALDokploy: Authenticated blind command injection via file mounts leads to direct remote host RCE on managed serversEPSS 0.5%CVE-2026-16793HIGHRemote Command Injection via OS Profile Password in Lenovo XClarity OrchestratorEPSS 0.5%CVE-2023-7338HIGHRuckus Unleashed Authenticated RCE in Gateway ModeEPSS 0.5%CVE-2024-20275MEDIUMCisco Secure Firewall Management Center Software Backup Cluster Command Injection VulnerabilityEPSS 0.5%CVE-2026-34940HIGHKubeAI has an OS Command Injection via Model URL in Ollama Engine startup probe allows arbitrary command execution in model podsEPSS 0.5%CVE-2019-15274MEDIUMCisco TelePresence Collaboration Endpoint Software Command Injection VulnerabilityEPSS 0.5%CVE-2026-82369HIGHInsufficient input sanitization of shell metacharacters in Brocade SANnav before 3.0.1aEPSS 0.5%CVE-2022-35976MEDIUMImproper KubeConfig handling allows arbitrary code executionEPSS 0.5%CVE-2026-79535MEDIUMmbailey VoiceMode <= 8.10.1 is vulnerable to OS Command Injection. The update_config MCP tool (and the "voicemode config set" CLI) writes a EPSS 0.5%CVE-2024-41956HIGHSoft Serve allows arbitrary code execution by crafting git-lfs requestsEPSS 0.5%CVE-2023-41838MEDIUMAn improper neutralization of special elements used in an os command ('os command injection') in FortiManager 7.4.0 and 7.2.0 through 7.2.3 EPSS 0.5%CVE-2025-41281HIGHNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in WateEPSS 0.5%