Fallos del tipo CWE-78

4669 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2026-42148LOWCoolify: Command Injection via Unescaped Version String in Docker BuildEPSS 0.2%CVE-2026-41011HIGHPackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz") and name = package_EPSS 0.2%CVE-2025-6181HIGHThe StrongDM Windows service incorrectly handled input validation. Authenticated attackers could potentially exploit this leading to privileEPSS 0.2%CVE-2026-102925HIGHvirtualenv bash and fish activation scripts execute commands embedded in pathsEPSS 0.2%CVE-2026-104859HIGHNx: OS command injection in the @nx/docker release pipelineEPSS 0.1%CVE-2026-17133HIGHIBM App Connect Enterprise Toolkit is vulnerable to arbitrary code execution due to multiple CVEsEPSS 0.1%CVE-2026-101032HIGHnavi through 2.24.0 OS Command Injection via Cheatsheet VariablesEPSS 0.1%CVE-2026-95519HIGHRpm: code execution via macro expansion of manifest entries in `rpmgi` (`-q -p` / verify manifest flows)EPSS 0.1%CVE-2026-79992HIGHEmacs: emacs: command injection via crafted filenames in trampEPSS 0.1%CVE-2026-73077HIGHVim: Arbitrary Code Execution via Shell Keyword LookupEPSS 0.1%CVE-2026-102937HIGHvirtualenv: Command injection via --prompt in activate.bat (batch activator)EPSS 0.1%CVE-2026-77585MEDIUMImproper Validation of SSH Target in Okta Privileged Access ClientEPSS 0.1%CVE-2026-102120HIGHKiteworks Core OS Command InjectionEPSS 0.1%CVE-2026-19515HIGHOS Command Injection via Unit Test Execution in WSO2 Integrator MI VS Code Extension Allows Arbitrary Command ExecutionEPSS 0.1%CVE-2026-20008MEDIUMCisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Lua Code Injection VulnerabilityEPSS 0.1%CVE-2026-85288MEDIUMNotepad++: Shortcuts.xml macro HMAC bypass still reachable via the "Run a Macro Multiple Times" dialogEPSS 0.1%CVE-2026-91837HIGHNetworkmanager-iodine: networkmanager-iodine: local privilege escalation to root via nameserver option injectionEPSS 0.1%CVE-2026-16826MEDIUMIBM i is Affected By Multiple Vulnerabilities in Debug ServerEPSS 0.1%CVE-2026-85082HIGHMaple Media Root Browser Classic 3.3.0 - OS command injection through crafted SQLite filenamesEPSS 0.1%CVE-2026-17499MEDIUMIBM i is Affected By Multiple Vulnerabilities in Debug ServerEPSS 0.1%