Falhas do tipo CWE-78
4.641 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2026-48997HIGHe107: Command Injection via shell expansion in ImageMagick resize destination pathEPSS 1.3%CVE-2023-29048HIGHA component for parsing OXMF templates could be abused to execute arbitrary system commands that would be executed as the non-privileged runEPSS 1.3%CVE-2025-47212MEDIUMQTS, QuTS heroEPSS 1.3%CVE-2024-45885HIGHDrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameEPSS 1.3%CVE-2024-45891HIGHDrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameEPSS 1.3%CVE-2022-25890HIGHAll versions of the package wifey are vulnerable to Command Injection via the connect() function due to improper input sanitization.
EPSS 1.3%CVE-2022-24431HIGHCommand InjectionEPSS 1.3%CVE-2026-40029HIGHparseusbs < 1.9 Command Injection via Crafted LNK FilenameEPSS 1.3%CVE-2026-0596CRITICALCommand Injection in mlflow/mlflowEPSS 1.3%CVE-2020-12149MEDIUMOS Command Injection - Management File UploadEPSS 1.3%CVE-2024-44678HIGHGigastone TR1 Travel Router R101 v1.0.2 is vulnerable to Command Injection. This allows an authenticated attacker to execute arbitrary commaEPSS 1.3%CVE-2023-42788HIGHAn improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in FortiManager & FortiEPSS 1.3%CVE-2026-22223HIGHCommand Injection Vulnerability on TP-Link Archer BE230 v1.2 and BE3600 v1EPSS 1.3%CVE-2023-33239HIGHSecond Order Command-injection Vulnerability in the Key-generation FunctionEPSS 1.3%CVE-2023-3939CRITICALMultiple command injection in ZkTeco-based OEM devicesEPSS 1.3%CVE-2025-47856HIGHTwo improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoiEPSS 1.3%CVE-2022-43907HIGHIBM Security Guardium command executionEPSS 1.3%CVE-2023-23779MEDIUMMultiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiWeb verEPSS 1.3%CVE-2025-14204MEDIUMTykoDev cherry-studio-TykoFork OAuth Server Discovery oauth-authorization-server redirectToAuthorization os command injectionEPSS 1.3%CVE-2024-6507HIGHDeep Lake Kaggle command injectionEPSS 1.3%