Fallos del tipo CWE-78

4668 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2026-41421HIGHSiYuan Desktop Notification XSS Leads to Electron RCEEPSS 0.2%CVE-2026-62982HIGHGlances: Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values (process 'cmdline') → OS command injectionEPSS 0.2%CVE-2026-55580HIGHmcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode AllowlistEPSS 0.2%CVE-2026-22169HIGHOpenClaw < 2026.2.22 - Allowlist Bypass via sort Configuration in safeBinsEPSS 0.2%CVE-2025-12122MEDIUMPopup Box – Easily Create WordPress Popups <= 3.2.12 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.2%CVE-2023-20193MEDIUMA vulnerability in the Embedded Service Router (ESR) of Cisco ISE could allow an authenticated, local attacker to read, write, or delete arbEPSS 0.2%CVE-2026-10544MEDIUMImproper neutralization of special elements in the built-in PAM provider password rotation templates in Devolutions Server allows an authentEPSS 0.2%CVE-2026-78424HIGHOS Command Injection in Packet-Capture (Sniffer) Filter leading to Remote Code Execution on Kubernetes NodesEPSS 0.2%CVE-2026-17262MEDIUMIBM i is Affected By Denial of Service and Security Restriction Bypass Vulnerabilities in FTP [, ]EPSS 0.2%CVE-2026-84233HIGHRpm: command execution via macro expansion in `rpmuncompress -x` for crafted `.gem` filenamesEPSS 0.2%CVE-2026-75056HIGHIn JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possibleEPSS 0.2%CVE-2026-42290HIGHprotobufjs-cli: OS Command InjectionEPSS 0.2%CVE-2025-20308MEDIUMCisco Spaces Connector Privilege Escalation VulnerabilityEPSS 0.2%CVE-2026-44106HIGHLocal Privilege Escalation vulnerability in /etc/init.d/user-applications via customer website fileEPSS 0.2%CVE-2026-44099HIGHLocal Privilege Escalation via pppd password injectionEPSS 0.2%CVE-2026-44095HIGHLocal Privilege Escalation via Network scriptsEPSS 0.2%CVE-2026-48098HIGHNexTOR IP Changer Unsafely Uses sudo and shell=TrueEPSS 0.2%CVE-2026-44093HIGHLocal Privilege Escalation vulnerability in /etc/init.d/user-applications via user-application start scriptEPSS 0.2%CVE-2026-44096HIGHudhcpc Privilege EscalationEPSS 0.2%CVE-2026-16932HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.2%