Falhas do tipo CWE-78

4.665 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2026-72865CRITICALDokploy: OS Command Injection via compose `composePath`EPSS 0.7%CVE-2026-42153HIGHCoolify: PostgreSQL Healthcheck Command Injection Allows Root Code Execution in ContainerEPSS 0.7%CVE-2026-73263CRITICALProwler: RCE on Prowler App workers via kubeconfig auth-provider cmd-pathEPSS 0.7%CVE-2026-34058HIGHCoolify: OS Command Injection via Unmanaged Container Operations - Remote Code ExecutionEPSS 0.7%CVE-2026-34152HIGHCoolify: Command Injection via Newline in Pre/Post Deployment Commands (Heredoc Transport)EPSS 0.7%CVE-2026-73294CRITICALSemaphore U: OS Command InjectionEPSS 0.7%CVE-2026-42204HIGHCoolify: Authenticated RCE via SHELL_SAFE_COMMAND_PATTERN regression → host rootEPSS 0.7%CVE-2024-31162HIGHASUS Download Master - OS Command InjectionEPSS 0.6%CVE-2025-22366HIGHMennekes smart/premium charges systems, Command injection in firmware upgradeEPSS 0.6%CVE-2025-22368HIGHMennekes smart/premium charges systems, Command injection in sCU firmware updateEPSS 0.6%CVE-2026-59910HIGHDell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InEPSS 0.6%CVE-2025-25039MEDIUMAuthenticated Remote Command Injection in HPE Aruba Networking ClearPass Policy Manager Web-Based Management InterfaceEPSS 0.6%CVE-2026-56686HIGHDell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InEPSS 0.6%CVE-2025-22367HIGHMennekes smart/premium charges systems, Command injection in time settingEPSS 0.6%CVE-2025-41663CRITICALWeidmueller: Security routers IE-SR-2TX are affected by Command InjectionEPSS 0.6%CVE-2024-22228HIGH Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cifssupport utility. An authenticated attackerEPSS 0.6%CVE-2025-65882CRITICALAn issue was discovered in openmptcprouter thru 0.64 in file common/package/utils/sys-upgrade-helper/src/tools/sysupgrade.c in function creaEPSS 0.6%CVE-2023-49691HIGHA vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.0), RUGGEDCOM RM1224 LTE(4G) NAM EPSS 0.6%CVE-2024-24431HIGHA reachable assertion in the ogs_nas_emm_decode function of Open5GS v2.7.0 allows attackers to cause a Denial of Service (DoS) via a craftedEPSS 0.6%CVE-2026-67324CRITICALGitPython 3.1.50 Authentication Bypass via Joined Short OptionsEPSS 0.6%