Falhas do tipo CWE-78
4.653 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2023-39471HIGHTP-Link TL-WR841N ated_tp Command Injection Remote Code Execution VulnerabilityEPSS 0.9%CVE-2025-5743HIGHCWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
vulnerability exists that could cause remEPSS 0.9%CVE-2026-71472CRITICALAcm-search-v2-rhel9: search-v2-operator: shell-command and sql injection in postgresql-start.sh via cr-supplied work_memEPSS 0.9%CVE-2026-16466HIGHDataStage on Cloud Pak for Data has several vulnerabilities due to open source softwareEPSS 0.9%CVE-2025-6562HIGHHunt Electronic Hybrid DVR - OS Command InjectionEPSS 0.9%CVE-2023-37407HIGHIBM Aspera Orchestrator command executionEPSS 0.9%CVE-2025-30264HIGHQTS, QuTS heroEPSS 0.9%CVE-2026-0709HIGHSome Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input validation. Attackers withEPSS 0.9%CVE-2025-59534HIGHCryptoLib command Injection vulnerability in initialize_kerberos_keytab_file_login()EPSS 0.9%CVE-2026-58571HIGHDell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit thisEPSS 0.9%CVE-2026-58567HIGHDell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit thisEPSS 0.9%CVE-2026-33208HIGHRoxy-WI Vulnerable to Authenticated Remote Code Execution via OS Command Injection in find-in-config EndpointEPSS 0.9%CVE-2026-35463HIGHpyLoad has Improper Neutralization of Special Elements used in an OS CommandEPSS 0.9%CVE-2026-78177LOWTanStack devtools-vite Development Devtools Event Bus package-manager.ts installPackage os command injectionEPSS 0.9%CVE-2026-31994MEDIUMOpenClaw < 2026.2.19 - Local Command Injection via Unsafe cmd Argument Handling in Windows Scheduled Task Script GenerationEPSS 0.9%CVE-2026-35581HIGHEmissary has a Command Injection via PLACE_NAME Configuration in ExecutrixEPSS 0.9%CVE-2026-26009CRITICALCatalyst Affected by Remote Code Execution as Root via Containerized Install Script ExecutionEPSS 0.9%CVE-2023-6260HIGHWeb UI OS Command Injection in Brivo ACS100, ACS300EPSS 0.9%CVE-2025-9976CRITICALOS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025xEPSS 0.9%CVE-2026-25546HIGHGodot MCP is vulnerable to Command Injection via unsanitized projectPathEPSS 0.9%