Falhas do tipo CWE-77

2.816 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2026-19263MEDIUMINQUIRELAB mcp-bridge-api Servers Endpoint mcp-bridge.js command injectionEPSS 2.1%CVE-2026-90618MEDIUMGH05TCREW PentestAgent LocalRuntime runtime.py LocalRuntime.execute_command os command injectionEPSS 2.1%CVE-2025-29516HIGHD-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability via the backup functioEPSS 2.1%CVE-2026-5041MEDIUMcode-projects Chamber of Commerce Membership Management System pageMail.php fwrite command injectionEPSS 2.1%CVE-2026-85040MEDIUMZhongBangKeJi CRMEB Custom Scheduled Task Feature save eval os command injectionEPSS 2.1%CVE-2026-4537MEDIUMCudy TR1200 ipsec.lua action_ipsec_conn command injectionEPSS 2.1%CVE-2023-24331CRITICALCommand Injection vulnerability in D-Link Dir 816 with firmware version DIR-816_A2_v1.10CNB04 allows attackers to run arbitrary commands viaEPSS 2.1%CVE-2026-19041MEDIUMMissionSquad mcp-api NPM Package Version packages.ts this.packageService.installPackage command injectionEPSS 2.1%CVE-2024-28353HIGHThere is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands EPSS 2.1%CVE-2024-26204HIGHOutlook for Android Information Disclosure VulnerabilityEPSS 2.1%CVE-2026-7062MEDIUMIntina47 context-sync Git Integration git-integration.ts os command injectionEPSS 2.1%CVE-2026-79912MEDIUMTOTOLINK N600R cstecgi.cgi getCurrentTime command injectionEPSS 2.1%CVE-2026-76761MEDIUMchenhg5 cc-connect Management API engine.go shellExecCommand os command injectionEPSS 2.1%CVE-2026-7443MEDIUMBurtTheCoder mcp-dnstwist MCP index.ts fuzz_domain os command injectionEPSS 2.1%CVE-2026-7061MEDIUMToowiredd chatgpt-mcp-server MCP/HTTP docker.service.ts os command injectionEPSS 2.1%CVE-2026-5802MEDIUMidachev mcp-javadc HTTP os command injectionEPSS 2.1%CVE-2023-24157CRITICALA command injection vulnerability in the serverIp parameter in the function updateWifiInfo of TOTOLINK T8 V4.1.5cu allows attackers to execuEPSS 2.1%CVE-2026-7416MEDIUMPolarVista xcode-mcp-server MCP index.ts run_tests os command injectionEPSS 2.1%CVE-2026-14802MEDIUMreact create-react-app react-dev-utils openBrowser.js startBrowserProcess os command injectionEPSS 2.1%CVE-2023-24151CRITICALA command injection vulnerability in the ip parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1.5cu allows attackers to EPSS 2.1%