Falhas do tipo CWE-78
4.645 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2019-1627MEDIUMCisco Integrated Management Controller Information Disclosure VulnerabilityEPSS 1.2%CVE-2025-63705HIGHNPM package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js.EPSS 1.2%CVE-2023-51217HIGHAn issue discovered in TenghuTOS TWS-200 firmware version:V4.0-201809201424 allows a remote attacker to execute arbitrary code via crafted cEPSS 1.2%CVE-2026-40032HIGHUAC < 3.3.0-rc1 Command Injection via Placeholder SubstitutionEPSS 1.2%CVE-2023-52314CRITICALCommand injection in convert_shape_compareEPSS 1.2%CVE-2023-52311CRITICALCommand injection in _wget_downloadEPSS 1.2%CVE-2023-52310CRITICALCommand injection in get_online_pass_intervalEPSS 1.2%CVE-2026-23816HIGHAuthenticated Command Injection found in admin AOS-CX CLI commandEPSS 1.2%CVE-2024-39686CRITICALfishaudio/Bert-VITS2 Command Injection in webui_preprocess.py bert_gen functionEPSS 1.2%CVE-2024-29640CRITICALAn issue in aliyundrive-webdav v.2.3.3 and before allows a remote attacker to execute arbitrary code via a crafted payload to the sid parameEPSS 1.2%CVE-2023-47566MEDIUMQTS, QuTS hero, QuTScloudEPSS 1.2%CVE-2025-9174MEDIUMneurobin shc Filename shc.c make os command injectionEPSS 1.2%CVE-2024-23789CRITICALEnergy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attackeEPSS 1.2%CVE-2022-48616MEDIUMA Huawei data communication product has a command injection vulnerability. Successful exploitation of this vulnerability may allow attackersEPSS 1.2%CVE-2026-73165HIGHNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulneraEPSS 1.2%CVE-2020-15272HIGHShell-injection in git-tag-annotation GitHub actionEPSS 1.2%CVE-2023-41352HIGHChunghwa Telecom NOKIA G-040W-Q - Command InjectionEPSS 1.2%CVE-2022-2251MEDIUMImproper sanitization of branch names in GitLab Runner affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.EPSS 1.2%CVE-2026-73163HIGHNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulneraEPSS 1.2%CVE-2026-73176HIGHNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulneraEPSS 1.2%