Fallos del tipo CWE-78

4668 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2026-68519HIGHGlances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)EPSS 0.2%CVE-2024-21782MEDIUMBIG-IP and BIG-IQ secure copy vulnerabilityEPSS 0.2%CVE-2023-53158MEDIUMThe gix-transport crate before 0.36.1 for Rust allows command execution via the "gix clone 'ssh://-oProxyCommand=open$IFS" substring. NOTE: EPSS 0.2%CVE-2026-34779MEDIUMElectron: AppleScript injection in app.moveToApplicationsFolder on macOSEPSS 0.2%CVE-2023-43066MEDIUM Dell Unity prior to 5.3 contains a Restricted Shell Bypass vulnerability. This could allow an authenticated, local attacker to exploit thisEPSS 0.2%CVE-2025-54595HIGHPearcleaner's unauthenticated access to privileged XPC helper allows root command executionEPSS 0.2%CVE-2025-20220MEDIUMA vulnerability in the CLI of Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure Firewall Threat Defense (FTD) SoftwareEPSS 0.2%CVE-2026-68939LOWPyenv: Glob/wildcard metacharacters bypass is_version_safe(), causing silent version/interpreter substitution via unquoted expansion (CVE-2022-35861 residual)EPSS 0.2%CVE-2026-68518HIGHGlances: Command injection bypass of action-template sanitizer via cross-field shell-operator reconstructionEPSS 0.2%CVE-2026-20040HIGHCisco IOS XR Software CLI Privilege Escalation VulnerabilityEPSS 0.2%CVE-2026-49219MEDIUMImageMagick: Policy Bypass can read disallowed filesEPSS 0.2%CVE-2026-10805MEDIUMNetworkmanager: networkmanager: local privilege escalation via malformed mud urls in dhclient backendEPSS 0.2%CVE-2026-87088HIGHTanium addressed an unauthorized code execution vulnerability in Enforce.EPSS 0.2%CVE-2025-20213MEDIUMCisco Catalyst SDWAN Manager Arbitrary File Overwrite VulnerabilityEPSS 0.2%CVE-2026-41010HIGHReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@release_dir, 'jobs', "#{name}.tgz") where EPSS 0.2%CVE-2026-90894HIGHParallels Desktop local privilege escalation via appliance extract argument injectionEPSS 0.2%CVE-2025-54314LOWThor before 1.4.0 can construct an unsafe shell command from library input. NOTE: this is disputed by the Supplier because "the method that EPSS 0.2%CVE-2025-6183HIGHConfigd InjectionEPSS 0.2%CVE-2026-67180HIGHGoogle Turbinia arbitrary command executionEPSS 0.2%CVE-2026-55448MEDIUMmise: Local credential_command executes untrusted configEPSS 0.2%