Falhas do tipo CWE-78
4.657 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2026-48731HIGHWarp: Linux external editor command injectionEPSS 0.9%CVE-2026-25593HIGHOpenClaw Affected by Unauthenticated Local RCE via WebSocket config.applyEPSS 0.9%CVE-2024-5785HIGHCommand injection vulnerability in Comtrend routerEPSS 0.9%CVE-2021-26616HIGHSecuwaySSL OS command injection vulnerabilityEPSS 0.9%CVE-2024-22224HIGH
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_nas utility. An authenticated attacker could pEPSS 0.9%CVE-2024-42922MEDIUMAAPanel v7.0.7 was discovered to contain an OS command injection vulnerability.EPSS 0.9%CVE-2026-28391CRITICALOpenClaw < 2026.2.2 - Command Injection via cmd.exe Parsing Bypass in Allowlist EnforcementEPSS 0.9%CVE-2024-8360MEDIUMVisteon Infotainment REFLASH_DDU_ExtractFile Command Injection Remote Code Execution VulnerabilityEPSS 0.9%CVE-2024-8358MEDIUMVisteon Infotainment UPDATES_ExtractFile Command Injection Remote Code Execution VulnerabilityEPSS 0.9%CVE-2025-41279HIGHNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the EPSS 0.9%CVE-2025-41267HIGHNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the EPSS 0.9%CVE-2025-41266HIGHNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the EPSS 0.9%CVE-2025-41265HIGHNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the EPSS 0.9%CVE-2024-39935HIGHjc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authenticated user (with certificatEPSS 0.9%CVE-2026-18272MEDIUMKenwood DNR1007XR startUpdateProcess Command Injection VulnerabilityEPSS 0.9%CVE-2023-37861HIGHPHOENIX CONTACT: OS Command Injection in WP 6xxx Web panelsEPSS 0.9%CVE-2024-8359MEDIUMVisteon Infotainment REFLASH_DDU_FindFile Command Injection Remote Code Execution VulnerabilityEPSS 0.9%CVE-2024-22223HIGH
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_cbr utility. An authenticated malicious usEPSS 0.9%CVE-2023-34980MEDIUMQTS, QuTS heroEPSS 0.9%CVE-2026-72767HIGHn8n before 1.123.67 Remote Code Execution via Git nodeEPSS 0.9%