Fallos del tipo CWE-78

4668 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2022-40679HIGHAn improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 5.x all versions, 6.0 all versions, EPSS 0.2%CVE-2026-43943HIGHelecterm: RCE via malicious SSH server filename in openFileWithEditorEPSS 0.2%CVE-2025-12742HIGHRemote Code Execution in Looker via Teradata JDBC DriverEPSS 0.2%CVE-2026-81097HIGHrails-mcp-server 1.4.0 through 1.6.0 OS Command Execution via execute_ruby PTY EscapeEPSS 0.2%CVE-2026-55849HIGH@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized `--workspace` ArgumentEPSS 0.2%CVE-2026-89066HIGHOS command injection in the task synthesis component in projenEPSS 0.2%CVE-2024-47115HIGHIBM AIX command executionEPSS 0.2%CVE-2026-48097HIGHNexTOR_IP_CHANGER has PATH Injection Leading to Arbitrary Command ExecutionEPSS 0.2%CVE-2024-20289MEDIUMCisco NX-OS Software Command Injection VulnerabilityEPSS 0.2%CVE-2025-62801MEDIUMFastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_nameEPSS 0.2%CVE-2026-88886HIGHRenovate before 44.14.7 Command Injection via gradle-wrapperEPSS 0.2%CVE-2025-68922HIGHOpenOps before 0.6.11 allows remote code execution in the Terraform block.EPSS 0.2%CVE-2026-55895MEDIUMVim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filenameEPSS 0.2%CVE-2025-20138HIGHCisco IOS XR Software CLI Privilege Escalation VulnerabilityEPSS 0.2%CVE-2026-44463HIGHZed: Allowlist Bypass via Environment Variable Injection in Terminal Tool PermissionsEPSS 0.2%CVE-2026-44466HIGHZed: Allowlist Bypass via Bash Arithmetic Expansion in Terminal Tool PermissionsEPSS 0.2%CVE-2026-49260HIGHPhpWeasyPrint: shell command injection via configurable WeasyPrint binary path due to inverted is_executable() guard (mirror of KnpLabs/snappy GHSA-vpr4-p6fq-85jc)EPSS 0.2%CVE-2026-56389MEDIUMArbitrary Command Execution in GNU BisonEPSS 0.2%CVE-2026-0383HIGHInformation disclosure in Brocade Fabric OS before 9.2.1c2, 9.2.2 through 9.2.2a and 10.0.0EPSS 0.2%CVE-2025-12737HIGHArbitrary Code Execution via Administrative Operations in Multiple WSO2 Products Allows Remote Code ExecutionEPSS 0.2%