Fallos del tipo CWE-78

4665 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2025-47857MEDIUMA improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in Fortinet FortiWeb CLIEPSS 0.5%CVE-2020-3171HIGHCisco FXOS and UCS Manager Software Local Management CLI Command Injection VulnerabilityEPSS 0.5%CVE-2025-66572MEDIUMLoaded Commerce 6.6 Client-Side Template Injection (CSTI)EPSS 0.5%CVE-2026-72870HIGHDokploy: Command Injection via Docker Credentials in buildRemoteDockerEPSS 0.5%CVE-2026-72874HIGHDokploy: Command Injection via Unescaped Git URL in Clone CommandsEPSS 0.5%CVE-2026-72879CRITICALDokploy: Command Injection via Registry Credentials in Swarm UploadEPSS 0.5%CVE-2025-64109HIGHCursor CLI Beta: Command Injection via Untrusted MCP ConfigurationEPSS 0.5%CVE-2026-25706HIGHyast2-samba-client: OS command injection via attacker-controlled Organizational Unit (Active Directory-supplied)EPSS 0.5%CVE-2026-25723HIGHClaude Code Vulnerable to Command Injection via Piped sed Command Bypasses File Write RestrictionsEPSS 0.5%CVE-2021-1476MEDIUMCisco Adaptive Security Appliance Software and Firepower Threat Defense Software Command Injection VulnerabilityEPSS 0.5%CVE-2026-19843HIGH389-ds-base: 389-ds-base: command injection via unescaped ldap dn in cockpit 389 console ldap editorEPSS 0.5%CVE-2026-25041HIGHBudibase has a Command Injection in PostgreSQL Dump CommandEPSS 0.5%CVE-2025-13481HIGHIBM Aspera Orchestrator Command InjectionEPSS 0.5%CVE-2025-55284HIGHClaude Code's Permissive Default Allowlist Enables Unauthorized File Read and Network Exfiltration in Claude CodeEPSS 0.5%CVE-2023-2625CRITICALA vulnerability exists that can be exploited by an authenticated client that is connected to the same network segment as the CoreTec 4, haviEPSS 0.5%CVE-2026-72878CRITICALDokploy: OS Command Injection in backup/restore pipeline via unescaped user-controlled shell argumentsEPSS 0.5%CVE-2019-1769MEDIUMCisco NX-OS Software Line Card Command Injection VulnerabilityEPSS 0.5%CVE-2024-3798HIGHInsecure handling of GET argument in PhonieboxEPSS 0.5%CVE-2019-1776MEDIUMCisco NX-OS Software Command Injection VulnerabilityEPSS 0.5%CVE-2019-1778MEDIUMCisco NX-OS Software Command Injection VulnerabilityEPSS 0.5%