Falhas do tipo CWE-77

2.831 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2026-47708CRITICALMCP-for-Stata: Command injection via log_file_name parameter in Stata command wrapperEPSS 0.5%CVE-2026-47690HIGHMeltanoHub vulnerable to command injection in the `test_dispatcher` GitHub Actions workflowEPSS 0.5%CVE-2026-23779MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release verEPSS 0.5%CVE-2019-1735MEDIUMCisco NX-OS Software Command Injection Vulnerability (CVE-2019-1735)EPSS 0.5%CVE-2024-38817MEDIUMVMware NSX contains a command injection vulnerability.  A malicious actor with access to the NSX Edge CLI terminal may be able to craft malEPSS 0.5%CVE-2026-42257MEDIUMnet-imap: Command Injection via "raw" arguments to multiple commandsEPSS 0.5%CVE-2024-56837HIGHA vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGEEPSS 0.5%CVE-2026-22623HIGHDue to insufficient input parameter validation on the interface, authenticated users of certain HIKSEMI NAS products can execute arbitrary cEPSS 0.5%CVE-2024-52011HIGHlaunch-editor vulnerable to command injection via the crafted request on WindowsEPSS 0.5%CVE-2024-32884MEDIUMgix-transport indirect code execution via malicious usernameEPSS 0.5%CVE-2025-59818CRITICALAuthenticated Remote Code Execution via the file name of an uploaded fileEPSS 0.5%CVE-2019-1623MEDIUMCisco Meeting Server CLI Command Injection VulnerabilityEPSS 0.5%CVE-2026-41611HIGHVisual Studio Code Remote Code Execution VulnerabilityEPSS 0.5%CVE-2019-1791MEDIUMCisco NX-OS Software Command Injection VulnerabilityEPSS 0.5%CVE-2025-20334HIGHA vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker to inject commands that will execute with rEPSS 0.5%CVE-2026-75007MEDIUMIn Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitutEPSS 0.5%CVE-2019-17148HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop version 14EPSS 0.5%CVE-2024-22545HIGHAn issue was discovered in TRENDnet TEW-824DRU version 1.04b01, allows unauthenticated attackers to execute arbitrary code via the system.ntEPSS 0.5%CVE-2025-50461MEDIUMA deserialization vulnerability exists in Volcengine's verl 3.0.0, specifically in the scripts/model_merger.py script when using the "fsdp" EPSS 0.5%CVE-2018-0477—Cisco IOS XE Software Command Injection VulnerabilitiesEPSS 0.5%