Falhas do tipo CWE-77

2.829 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2025-59272CRITICALCopilot Information Disclosure VulnerabilityEPSS 0.6%CVE-2025-59252CRITICALM365 Copilot Information Disclosure VulnerabilityEPSS 0.6%CVE-2025-59286CRITICALCopilot Information Disclosure VulnerabilityEPSS 0.6%CVE-2026-10195HIGHFS Poster <= 8.0.1 - Authenticated (Subscriber+) Remote Code Execution via FFmpeg Path SettingEPSS 0.6%CVE-2026-23814HIGHAuthenticated Command Injection found in AOS-CX CLI CommandEPSS 0.6%CVE-2026-40068HIGHClaude Code arbitrary code execution via git worktree commondir trust dialog bypassEPSS 0.6%CVE-2024-57036HIGHTOTOLINK A810R V4.1.2cu.5032_B20200407 was found to contain a command insertion vulnerability in downloadFile.cgi main function. This vulnerEPSS 0.6%CVE-2024-33439CRITICALAn issue in Kasda LinkSmart Router KW5515 v1.7 and before allows an authenticated remote attacker to execute arbitrary OS commands via cgi pEPSS 0.6%CVE-2024-58354HIGHcal.com Repository Takeover via pull_request_target WorkflowEPSS 0.6%CVE-2023-49716MEDIUMEmerson Rosemount GC370XA, GC700XA, GC1500XA Command InjectionEPSS 0.6%CVE-2024-53412HIGHCommand injection in the connect function in NietThijmen ShoppingCart 0.0.2 allows an attacker to execute arbitrary shell commands and achieEPSS 0.6%CVE-2020-3266HIGHCisco SD-WAN Solution Command Injection VulnerabilityEPSS 0.6%CVE-2024-51258HIGHDrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the EPSS 0.6%CVE-2024-48145CRITICALA prompt injection vulnerability in the chatbox of Netangular Technologies ChatNet AI Version v1.0 allows attackers to access and exfiltrateEPSS 0.6%CVE-2026-41265CRITICALFlowise: Airtable_Agent Code Injection Remote Code Execution VulnerabilityEPSS 0.6%CVE-2024-48144CRITICALA prompt injection vulnerability in the chatbox of Fusion Chat Chat AI Assistant Ask Me Anything v1.2.4.0 allows attackers to access and exfEPSS 0.6%CVE-2024-54660HIGHA JNDI injection issue was discovered in Cloudera JDBC Connector for Hive before 2.6.26 and JDBC Connector for Impala before 2.6.35. AttackeEPSS 0.6%CVE-2025-46735LOWTerraform WinDNS Provider improperly sanitizes input variables in `windns_record`EPSS 0.6%CVE-2024-20492MEDIUMCisco Expressway Series Privilege Escalation VulnerabilityEPSS 0.6%CVE-2025-22476MEDIUMDell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Neutralization of Special Elements used in a Command EPSS 0.5%