Fallos del tipo CWE-78

4668 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2026-43991HIGHJunoClaw: plugin-shell shell-injection bypass via substring blocklistEPSS 0.3%CVE-2026-44465HIGHZed: Zed IDE Arbitrary Code Execution via untrusted repository with poisoned .git/configEPSS 0.3%CVE-2023-20056MEDIUMCisco Access Point Software Denial of Service VulnerabilityEPSS 0.3%CVE-2026-24154HIGHNVIDIA Jetson Linux has vulnerability in initrd, where an unprivileged attacker with physical access coul inject incorrect command line arguEPSS 0.3%CVE-2024-54012HIGHCommand InjectionEPSS 0.3%CVE-2026-28463HIGHOpenClaw < 2026.2.14 - Arbitrary File Read via Shell Expansion in Safe Bins AllowlistEPSS 0.3%CVE-2025-43020MEDIUMPoly Clariti Manager - Multiple Security VulnerabilitiesEPSS 0.3%CVE-2026-57282MEDIUMJenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded into a generated SSH EPSS 0.3%CVE-2026-46709HIGHTabby: Drag-and-drop path injection still allows RCE via shell command substitution (incomplete fix for CVE-2026-45038)EPSS 0.3%CVE-2026-48703HIGHWarp: Command Injection via Warp code search tool argumentsEPSS 0.3%CVE-2023-20050MEDIUMCisco NX-OS Software CLI Command Injection VulnerabilityEPSS 0.3%CVE-2024-39521HIGHJunos OS Evolved: CLI parameter processing issue allows privilege escalationEPSS 0.3%CVE-2024-39523HIGHJunos OS Evolved: CLI parameter processing issue allows privilege escalationEPSS 0.3%CVE-2024-39524HIGHJunos OS Evolved: CLI parameter processing issue allows privilege escalationEPSS 0.3%CVE-2024-39522HIGHJunos OS Evolved: CLI parameter processing issue allows privilege escalationEPSS 0.3%CVE-2024-39520HIGHJunos OS Evolved: CLI parameter processing issue allows privilege escalationEPSS 0.3%CVE-2026-44461HIGHZed: Remote Command Injection via Unquoted Environment Variable Keys (SSH / WSL Remote)EPSS 0.2%CVE-2026-100559HIGHOpenClaw before 2026.8.1 Command Injection via Escaped NewlinesEPSS 0.2%CVE-2025-27079MEDIUMArbitrary File Creation vulnerability allows for Authenticated Remote Code Execution in CLI InterfaceEPSS 0.2%CVE-2023-40716MEDIUMAn improper neutralization of special elements used in an OS command vulnerability [CWE-78]  in the command line interpreter of FortiTester EPSS 0.2%