Fallos del tipo CWE-78

4668 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2026-79079HIGHAn issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c comEPSS 0.2%CVE-2026-55697HIGHpnpm: Repository-controlled configDependencies can select a pacquet native install engineEPSS 0.2%CVE-2026-19635HIGHLocal Privilege EscalationEPSS 0.2%CVE-2026-44076MEDIUMShell injection via volume pathEPSS 0.2%CVE-2024-8934MEDIUMBeckhoff: Local command injection via TwinCAT Package ManagerEPSS 0.2%CVE-2026-61898HIGHaccountsservice: shell injection via attacker-controlled ~/.pam_environment in Ubuntu language helper scriptsEPSS 0.2%CVE-2024-58278HIGHIndigoSTAR Software - perl2exe <= V30.10C - Arbitrary Code ExecutionEPSS 0.2%CVE-2024-50377MEDIUMA CWE-798 "Use of Hard-coded Credentials" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3)EPSS 0.2%CVE-2026-76055HIGHImproper Neutralization of Special Elements used in an OS Command in the package manager component of Black Duck blackduck-c-cpp before 3.0.EPSS 0.2%CVE-2025-20295MEDIUMCisco UCS Manager Software Command Injection VulnerabilityEPSS 0.2%CVE-2026-55441HIGHmise: Arbitrary command execution via task-include files in an untrusted, config-less repositoryEPSS 0.2%CVE-2026-76802MEDIUMNuclei: Arbitrary Command Execution via DAST Code Signature BypassEPSS 0.2%CVE-2024-20461MEDIUMCisco ATA 190 Series Analog Telephone Adapter Firmware Command Injection VulnerabilityEPSS 0.2%CVE-2025-40582HIGHA vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge ClientEPSS 0.2%CVE-2025-60013MEDIUMF5OS-A FIPS HSM password vulnerabilityEPSS 0.2%CVE-2026-48122MEDIUMWorkspace settings can override executable and Gemfile paths used by the Ruby LSP VS Code extensionEPSS 0.2%CVE-2026-70611MEDIUMElectron: DevTools embedder handler executes arbitrary files via shell openEPSS 0.2%CVE-2026-55798MEDIUMPillow: WindowsViewer.get_command() OS command injection via unescaped shell pathEPSS 0.2%CVE-2026-14852MEDIUMmk_sap_hana: Privilege escalation via crafted sapstartsrv process nameEPSS 0.2%CVE-2026-45036HIGHTabby auto-confirms ZMODEM detection on terminal output, leading to shell command execution from displayed file content under fish, bash, and zshEPSS 0.2%