Falhas do tipo CWE-77

2.814 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2025-2367MEDIUMOiwtech OIW-2431APGN-HP Personal Script Submenu formScript os command injectionEPSS 1.4%CVE-2024-42506CRITICALUnauthenticated Command Injection Vulnerabilities in the CLI Service Accessed by the PAPI ProtocolEPSS 1.4%CVE-2026-6219MEDIUMaandrew-me ytDownloader Compressor Feature compressor.js child_process.exec command injectionEPSS 1.4%CVE-2024-42507CRITICALUnauthenticated Command Injection Vulnerabilities in the CLI Service Accessed by the PAPI ProtocolEPSS 1.4%CVE-2026-4496MEDIUMsigmade Git-MCP-Server gitUtils.ts child_process.exec os command injectionEPSS 1.4%CVE-2024-3154HIGHCri-o: arbitrary command injection via pod annotationEPSS 1.4%CVE-2026-44867HIGHAuthenticated Command Injection Vulnerabilities in the Web-Based Management Interface of AOS-8 and AOS-10EPSS 1.4%CVE-2026-44869HIGHAuthenticated Command Injection Vulnerabilities in the Web-Based Management Interface of AOS-8 and AOS-10EPSS 1.4%CVE-2026-44868HIGHAuthenticated Command Injection Vulnerabilities in the Web-Based Management Interface of AOS-8 and AOS-10EPSS 1.4%CVE-2026-44870HIGHAuthenticated Command Injection Vulnerabilities in Command Line Interface (CLI) Service Accessed by PAPI Protocol of AOS-8 and AOS-10 Operating SystemsEPSS 1.4%CVE-2026-44871HIGHAuthenticated Command Injection Vulnerabilities in Command Line Interface (CLI) Service Accessed by PAPI Protocol of AOS-8 and AOS-10 Operating SystemsEPSS 1.4%CVE-2026-44866HIGHAuthenticated Command Injection Vulnerabilities in the Web-Based Management Interface of AOS-8 and AOS-10EPSS 1.4%CVE-2026-5621MEDIUMChrisChinchilla Vale-MCP HTTP index.ts os command injectionEPSS 1.4%CVE-2026-5619MEDIUMBraffolk mcp-summarization-functions summarize_command mcp-server.ts os command injectionEPSS 1.4%CVE-2026-8210MEDIUMaandrew-me tgpt Update helper.go helper.Update command injectionEPSS 1.4%CVE-2024-27980HIGHDue to the improper handling of batch files in child_process.spawn / child_process.spawnSync, a malicious command line argument can inject aEPSS 1.4%CVE-2026-21518HIGHGitHub Copilot and Visual Studio Code Security Feature Bypass VulnerabilityEPSS 1.4%CVE-2023-33486CRITICALTOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setOpModeCfg. This vulnerabilEPSS 1.4%CVE-2023-33487CRITICALTOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a command insertion vulnerability in setDiagnosisCfg.This vulneraEPSS 1.4%CVE-2020-26300MEDIUMCommand injection in systeminformationEPSS 1.4%