Falhas do tipo CWE-78
4.664 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2026-27113MEDIUMLiquid Prompt arbitrary command injection via crafted Git branch names in gitstatusd backendEPSS 0.8%CVE-2026-44190HIGHAnsible-lightspeed: ansible lightspeed visual studio code extension: arbitrary code execution via command injection in activation script settingEPSS 0.8%CVE-2022-27486MEDIUMA improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiDDoS version 5.5.0 through 5.5EPSS 0.8%CVE-2026-81552HIGHDataStage on Cloud Pak for Data has several vulnerabilitiesEPSS 0.8%CVE-2026-81548HIGHDataStage on Cloud Pak for Data has several vulnerabilitiesEPSS 0.8%CVE-2020-37002HIGHAjenti 2.1.36 Authenticated Remote Code ExecutionEPSS 0.8%CVE-2026-101045HIGHFleet Homebrew Cask OS Command Injection via MetadataEPSS 0.8%CVE-2025-48204MEDIUMThe ns_backup extension through 13.0.0 for TYPO3 allows command injection.EPSS 0.8%CVE-2026-17497HIGHNoteGen arbitrary OS command execution via Tauri shell:allow-execute for bash/pythonEPSS 0.7%CVE-2021-4029HIGHA command injection vulnerability in the CGI program of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary OS commaEPSS 0.7%CVE-2025-57771HIGHRoo-Code potential remote code execution via auto-execute command parsing flawEPSS 0.7%CVE-2025-31693MEDIUMAI (Artificial Intelligence) - Moderately critical - Gadget Chain - SA-CONTRIB-2025-022EPSS 0.7%CVE-2024-43402HIGHRust OS Command Injection/Argument Injection vulnerabilityEPSS 0.7%CVE-2025-27262HIGHEricsson Indoor Connect 8855 - Improper Neutralization of Special Elements used in an OS Command VulnerabilityEPSS 0.7%CVE-2023-34215HIGHSecond Order Command-injection Vulnerability in the Certificate-generation FunctionEPSS 0.7%CVE-2026-32311CRITICALCommand Injection and Docker container escape allows root on host machineEPSS 0.7%CVE-2024-46890CRITICALA vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate inpEPSS 0.7%CVE-2026-54699HIGHWarp: OS command injection when opening terminal links from WSLEPSS 0.7%CVE-2026-0758HIGHmcp-server-siri-shortcuts shortcutName Command Injection Privilege Escalation VulnerabilityEPSS 0.7%CVE-2026-73483CRITICALFlowise before 3.1.3 Sandbox Escape via PuppeteerEPSS 0.7%