Fallos del tipo CWE-78

4668 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2026-9560CRITICALPrivilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands wEPSS 0.4%CVE-2026-30309HIGHInfCode's terminal auto-execution module contains a critical command filtering vulnerability that renders its blacklist security mechanism cEPSS 0.4%CVE-2026-25621HIGHArista Edge Threat Management NGFW Reports Application Insecure Input ValidationEPSS 0.4%CVE-2023-20082MEDIUMCisco IOS XE Software for Cisco Catalyst 9300 Series Switches Secure Boot Bypass VulnerabilityEPSS 0.4%CVE-2026-31999MEDIUMOpenClaw 2026.2.26 < 2026.3.1 - Current Working Directory Injection via Windows Wrapper Resolution FallbackEPSS 0.4%CVE-2021-1452MEDIUMCisco IOS XE ROM Monitor Software for Cisco Industrial Switches OS Command Injection VulnerabilityEPSS 0.4%CVE-2026-15816HIGHDracut: dracut: root code execution via unescaped error message written to sourced emergency hook script in die()EPSS 0.4%CVE-2026-17420MEDIUMIBM i is Affected By Multiple Vulnerabilities in SQLEPSS 0.4%CVE-2025-64106HIGHCursor: Speedbump Modal Bypass in MCP Server Deep-LinkEPSS 0.4%CVE-2019-1725MEDIUMCisco UCS B-Series Blade Servers Local Management CLI Arbitrary File Creation or CLI Parameter Injection VulnerabilityEPSS 0.4%CVE-2025-54133MEDIUMCursor's MCP Install Deeplink Does Not Show Arguments in its User-DialogEPSS 0.4%CVE-2026-86035HIGHWeblate: Mercurial argument injection via repository filenames allows authenticated command executionEPSS 0.4%CVE-2023-23693MEDIUM Dell VxRail, versions prior to 7.0.450, contains an OS command injection Vulnerability in DCManager command-line utility. A local high privEPSS 0.4%CVE-2025-64091HIGHAuthenticated Remote Code Execution in the NTP-configurationEPSS 0.4%CVE-2026-54344MEDIUMToolJet GitHub Actions comment body shell injection exposes deployment secretsEPSS 0.4%CVE-2026-23882HIGHBlinko: Admin RCE - MCP Server Command InjectionEPSS 0.4%CVE-2025-20349MEDIUMCisco DNA Center API Command Injection VulnerabilityEPSS 0.4%CVE-2024-38471MEDIUMMultiple TP-LINK products allow a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by restoring aEPSS 0.4%CVE-2025-53637MEDIUMMeshtastic allows Command Injection in GitHub ActionEPSS 0.4%CVE-2026-86530HIGHBUFFALO Wi-Fi products handle some web form input improperly to assemble command line strings internally. An administrative user may send a EPSS 0.4%