Falhas do tipo CWE-78
4.665 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2024-26012MEDIUMA improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiAP-S 6.2 all verisons, and 6.4EPSS 0.7%CVE-2024-26258HIGHOS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with credentials to execute arbitrary OEPSS 0.7%CVE-2026-27965HIGHVitess users with backup storage access can gain unauthorized access to production deployment environmentsEPSS 0.7%CVE-2026-77084HIGHn8n before 1.123.69 Remote Code Execution via Git Node Configuration ValuesEPSS 0.7%CVE-2024-51249HIGHIn Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the reEPSS 0.7%CVE-2024-51253HIGHIn Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doEPSS 0.7%CVE-2024-30414HIGHCommand injection vulnerability in the AccountManager module.
Impact: Successful exploitation of this vulnerability may affect service confiEPSS 0.7%CVE-2026-33613HIGHMB connect line mbCONNECT24 vulnerable to RCE in generateSrpArrayEPSS 0.7%CVE-2026-55607HIGHClaude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code ExecutionEPSS 0.7%CVE-2024-58376HIGHRenovate 37.158.0 before 37.199.0 Command Injection via helmv3EPSS 0.7%CVE-2024-50361HIGHA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 0.7%CVE-2025-6541HIGHOS command injection using information obtained from the web management interfaceEPSS 0.7%CVE-2026-16524HIGHPcp: pcp linux_sockets pmda: arbitrary command execution via command injectionEPSS 0.7%CVE-2023-34138HIGHA command injection vulnerability in the hotspot management feature of the Zyxel ATP series firmware versions 4.60 through 5.36 Patch 2, USGEPSS 0.7%CVE-2023-34141HIGHA command injection vulnerability in the access point (AP) management feature of the Zyxel ATP series firmware versions 5.00 through 5.36 PaEPSS 0.7%CVE-2026-93289CRITICALOS command injection in Eufy Omni C20, Omni X10 ProEPSS 0.7%CVE-2017-20236CRITICALProSoft Technology ICX35-HWC Command Injection via Web InterfaceEPSS 0.7%CVE-2026-25763CRITICALCommand Injection on OpenProject repositories leads to Remote Code ExecutionEPSS 0.7%CVE-2024-47821CRITICALpyLoad vulnerable to remote code execution by download to /.pyload/scripts using /flashgot APIEPSS 0.7%CVE-2025-66626HIGHargoproj/argo-workflows is vulnerable to RCE via ZipSlip and symbolic linksEPSS 0.7%