Fallos del tipo CWE-78

4665 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2026-49492HIGHMarkdown Preview Enhanced OS Command Injection in External File and Link OpeningEPSS 0.5%CVE-2022-41751HIGHJhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 oEPSS 0.5%CVE-2026-55427HIGHCoder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`EPSS 0.5%CVE-2024-40895MEDIUMFFRI AMC versions 3.4.0 to 3.5.3 and some OEM products that implement/bundle FFRI AMC versions 3.4.0 to 3.5.3 allow a remote unauthenticatedEPSS 0.5%CVE-2022-35849HIGHAn improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiADC 7.1.0 thEPSS 0.5%CVE-2025-36606HIGHDell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nfssupport utility. An authenticated attacEPSS 0.5%CVE-2025-43943MEDIUMDell Cloud Disaster Recovery, version(s) prior to 19.20, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OEPSS 0.5%CVE-2025-69755HIGHAn issue in Neterbit NW-431F Router vNW-431F-20241014-IR03 allows a remote attacker to obtain sensitive information and execute arbitrary coEPSS 0.5%CVE-2026-75363MEDIUMAn issue in Comfast CF-WR630AX v.2.7.0.2 allows a remote attacker to execute arbitrary code via the /usr/bin/webmgnt, /cgi-bin/mbox-config, EPSS 0.5%CVE-2019-1775MEDIUMCisco NX-OS Software Command Injection VulnerabilityEPSS 0.5%CVE-2023-48668HIGH Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 on DDMC contain an OS command injection vulnerabiEPSS 0.5%CVE-2019-1774MEDIUMCisco NX-OS Software Command Injection VulnerabilityEPSS 0.5%CVE-2021-35031MEDIUMA vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware, which could allow EPSS 0.5%CVE-2026-91936HIGHFlowise before 3.1.4 Script Injection via Docker WorkflowsEPSS 0.5%CVE-2026-70335HIGHGitHub Copilot and Visual Studio Code Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2019-12709MEDIUMCisco IOS XR Software for Cisco ASR 9000 VMAN CLI Privilege Escalation VulnerabilityEPSS 0.5%CVE-2025-43884HIGHDell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Improper Neutralization of Special Elements used in an OS EPSS 0.5%CVE-2025-52988HIGHJunos OS and Junos OS Evolved: Privilege escalation to root via CLI command 'request system logout'EPSS 0.5%CVE-2026-39382CRITICALdbt has a Command Injection in Reusable Workflow via Unsanitized comment-body OutputEPSS 0.5%CVE-2026-72904CRITICALFirecrawl: Arbitrary file read via JSON Schema $ref expansionEPSS 0.5%