Falhas do tipo CWE-77

2.828 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2022-48259CRITICALThere is a system command injection vulnerability in BiSheng-WNM FW 3.0.0.325. Successful exploitation could allow attackers to gain higher EPSS 0.9%CVE-2026-20095MEDIUMCisco Integrated Management Controller Command Injection VulnerabilityEPSS 0.9%CVE-2024-26295HIGHVulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands onEPSS 0.9%CVE-2024-26294HIGHVulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands onEPSS 0.9%CVE-2026-30352CRITICALA remote code execution (RCE) vulnerability in the /devserver/start endpoint of leonvanzyl autocoder commit 79d02a allows attackers to execuEPSS 0.9%CVE-2026-72735CRITICALDokploy: Command injection in writeTraefikConfigRemote via shell interpolation of unescaped YAML in SSH remote executionEPSS 0.9%CVE-2025-7388HIGHAuthenticated Command Injection via configuration parameter manipulation in exposed RMI interfaceEPSS 0.9%CVE-2024-26296HIGHVulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands onEPSS 0.9%CVE-2024-4078CRITICALArbitrary Code Execution in parisneo/lollmsEPSS 0.9%CVE-2024-26298HIGHVulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands onEPSS 0.9%CVE-2024-26297HIGHVulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands onEPSS 0.9%CVE-2026-11487MEDIUMNeovim View Branch secure.lua M.read command injectionEPSS 0.9%CVE-2026-26136MEDIUMMicrosoft Copilot Information Disclosure VulnerabilityEPSS 0.9%CVE-2026-42824MEDIUMM365 Copilot Information Disclosure VulnerabilityEPSS 0.9%CVE-2026-42827MEDIUMM365 Copilot Information Disclosure VulnerabilityEPSS 0.9%CVE-2026-47285MEDIUMVisual Studio Code Information Disclosure VulnerabilityEPSS 0.9%CVE-2026-24712HIGHNorthern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection.EPSS 0.9%CVE-2026-7246HIGH[DISPUTED] Pallets Click contains a command injection via Unsanitized Filename "click.edit()"EPSS 0.9%CVE-2025-55319HIGHAgentic AI and Visual Studio Code Remote Code Execution VulnerabilityEPSS 0.9%CVE-2024-39577HIGHDell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contains an Improper Neutralization of Special Elements useEPSS 0.9%