Fallos del tipo CWE-78

4668 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2026-45393HIGHLocal privilege escalation to SYSTEM in Cribl Edge for WindowsEPSS 0.4%CVE-2026-27955MEDIUMCoolify: Command Injection via Single-Quote Breakout in `executeInDocker()`EPSS 0.4%CVE-2026-90444HIGHOS Command Injection in MalcolmEPSS 0.4%CVE-2026-8654HIGHImproper input validation in Delphix Continuous Data connectors allows an authenticated user to execute arbitrary operating system commands EPSS 0.4%CVE-2026-34955HIGHPraisonAI: Sandbox Escape via shell=True and Bypassable Blocklist in SubprocessSandboxEPSS 0.4%CVE-2025-67037HIGHLantronix EDS5000, G520, and X300 OS Command InjectionEPSS 0.4%CVE-2025-67036HIGHLantronix EDS5000, G520, and X300 OS Command InjectionEPSS 0.4%CVE-2026-79766CRITICALTermix: OS command injection in ACME/Let's Encrypt certificate-request handler via admin-controlled domain/emailEPSS 0.4%CVE-2025-3189MEDIUMStored Cross-Site Scripting (XSS) in DoWISPEPSS 0.4%CVE-2026-84256HIGHAn argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to exEPSS 0.4%CVE-2026-102422CRITICALshell-quote `quote()` command injection via a line terminator in a token after a `{ comment }` tokenEPSS 0.4%CVE-2025-43908MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 releasEPSS 0.4%CVE-2025-10239HIGHUnintended command execution via troubleshooting scripts in Progress FlowmonEPSS 0.4%CVE-2026-85439HIGHMOOS-IvP through 24.8.1 alogsplit Command Injection via Input PathnameEPSS 0.4%CVE-2024-10896MEDIUMLogo Slider < 4.5.0 - Contributor+ Stored XSSEPSS 0.4%CVE-2020-3459MEDIUMCisco FXOS Software for Firepower 4100/9300 Series Command Injection VulnerabilityEPSS 0.4%CVE-2025-70039CRITICALAn issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linagora Twake v2023.Q1.1EPSS 0.4%CVE-2026-33030HIGHNginx UI: Unencrypted Storage of DNS API Tokens and ACME Private KeysEPSS 0.4%CVE-2021-1370HIGHCisco IOS XR Software for Cisco 8000 Series Routers and Network Convergence System 540 Series Routers Privilege Escalation VulnerabilityEPSS 0.4%CVE-2026-9560CRITICALPrivilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands wEPSS 0.4%