Falhas do tipo CWE-77

2.829 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2024-27818HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS EPSS 0.7%CVE-2024-39703HIGHIn ThreatQuotient ThreatQ before 5.29.3, authenticated users are able to execute arbitrary commands by sending a crafted request to an API eEPSS 0.7%CVE-2026-93967MEDIUMaiyiyi121 SxDevOps Command services.py generate_host_task command injectionEPSS 0.7%CVE-2025-56425CRITICALAn issue was discovered in the AppConnector component version 10.10.0.183 and earlier of enaio 10.10, in the AppConnector component version EPSS 0.7%CVE-2021-32692CRITICALActivity Watch vulnerable to command execution on macOS via printAppTitle.scptEPSS 0.7%CVE-2026-54449HIGHLangBot: Authenticated RCE Via MCP ConfigurationEPSS 0.7%CVE-2022-4009HIGHIn affected versions of Octopus Deploy it is possible for a user to introduce code via offline package creationEPSS 0.7%CVE-2024-1417HIGHLocal Code Injection Vulnerability in AuthPoint Password Manager App for macOS SafariEPSS 0.7%CVE-2023-47268MEDIUMIn libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrary code on a host wheEPSS 0.7%CVE-2026-85885CRITICALMicrosoft 365 Copilot Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2026-20096MEDIUMCisco Integrated Management Controller Command Injection VulnerabilityEPSS 0.7%CVE-2023-47104CRITICALtinyfiledialogs (aka tiny file dialogs) before 3.15.0 allows shell metacharacters (such as a backquote or a dollar sign) in titles, messagesEPSS 0.7%CVE-2026-30617HIGHLangChain-ChatChat 0.3.1 contains a remote code execution vulnerability in its MCP STDIO server configuration and execution handling. A remoEPSS 0.7%CVE-2026-79754HIGHNuclio: Kaniko build tempDir command injectionEPSS 0.7%CVE-2021-1382MEDIUMCisco IOS XE SD-WAN Software Command Injection VulnerabilityEPSS 0.7%CVE-2025-53787HIGHMicrosoft 365 Copilot BizChat Information Disclosure VulnerabilityEPSS 0.7%CVE-2025-23119HIGHAn Improper Neutralization of Escape Sequences vulnerability could allow an Authentication Bypass with a Remote Code Execution (RCE) by a maEPSS 0.7%CVE-2026-42895MEDIUMMicrosoft Copilot Tampering VulnerabilityEPSS 0.7%CVE-2026-42893HIGHMicrosoft Outlook for iOS Tampering VulnerabilityEPSS 0.7%CVE-2026-8431CRITICALOps Manager RCE via webhook bodyEPSS 0.7%