Falhas do tipo CWE-77

2.819 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2026-5833MEDIUMawwaiid mcp-server-taskwarrior index.ts server.setRequestHandler command injectionEPSS 1.1%CVE-2026-16489MEDIUMjsforce SFDX Connection Registry sfdx.js _execCommand os command injectionEPSS 1.1%CVE-2026-19047MEDIUMNocteDefensor LudusMCP ludus_cli_execute cliWrapper.ts executeCommand command injectionEPSS 1.1%CVE-2026-19333MEDIUMNightTrek Supabase-MCP generate_types command injectionEPSS 1.1%CVE-2026-4198MEDIUMhypermodel-labs mcp-server-auto-commit index.ts getGitChanges command injectionEPSS 1.1%CVE-2026-3959MEDIUM0xKoda WireMCP Tshark CLI index.js server.tool os command injectionEPSS 1.1%CVE-2026-78430MEDIUMsworddut mcp-ffmpeg-helper Tool handlers.ts handleToolCall os command injectionEPSS 1.1%CVE-2026-19332MEDIUMNellyW8 MCP4EDA run_openlane/view_waveform command injectionEPSS 1.1%CVE-2026-4199MEDIUMbazinga012 mcp_code_executor index.ts installDependencies command injectionEPSS 1.1%CVE-2026-5603MEDIUMelgentos magento2-dev-mcp index.ts executeMagerun2Command os command injectionEPSS 1.1%CVE-2026-5125MEDIUMraine consult-llm-mcp server.ts child_process.execSync os command injectionEPSS 1.1%CVE-2026-16735MEDIUMrelease-it conventional-changelog Changelog File index.js writeChangelog os command injectionEPSS 1.1%CVE-2026-16630MEDIUMsyncfusion ej2-javascript-ui-controls package.json child_process.exec os command injectionEPSS 1.1%CVE-2026-16628MEDIUMoclif JIT Plugin Entry child_process.exec os command injectionEPSS 1.1%CVE-2026-19044MEDIUMLeeSinLiang godot-mcp create_scene/add_node index.ts executeOperation command injectionEPSS 1.1%CVE-2026-19329MEDIUMandreahaku codex_mcp ask MCP Tool codex-process-simple.ts command injectionEPSS 1.1%CVE-2026-15669MEDIUMlouisho5 picobot exec Tool exec.go ExecTool.Execute os command injectionEPSS 1.1%CVE-2024-25081MEDIUMSplinefont in FontForge through 20230101 allows command injection via crafted filenames.EPSS 1.1%CVE-2022-20851MEDIUMCisco IOS XE Software Web UI Command Injection VulnerabilityEPSS 1.1%CVE-2026-5023MEDIUMDeDeveloper23 codebase-mcp RepoMix codebase.ts saveCodebase os command injectionEPSS 1.1%