Falhas do tipo CWE-78

4.668 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2026-59960HIGHArgos JavaScript: CI Branch Name OS Command Injection in @argos-ci/coreEPSS 0.6%CVE-2024-13502CRITICALA command injection in the NTC2218, NTC2250, NTC2299 modems' web interfaces allows to exeucte arbitrary shell commands.EPSS 0.6%CVE-2026-22176MEDIUMOpenClaw < 2026.2.19 - Command Injection via Unescaped Environment Variables in Windows Scheduled Task Script GenerationEPSS 0.6%CVE-2026-84832HIGHUnsafe deserialization in the REST interfaceEPSS 0.6%CVE-2024-34013HIGHLocal privilege escalation due to OS command injection vulnerability. The following products are affected: Acronis True Image (macOS) beforeEPSS 0.6%CVE-2024-52058HIGHPotential arbitrary command execution in System Designer while parsing malicious HTTP/REST requestsEPSS 0.6%CVE-2026-34937HIGHPraisonAI: Shell Injection in run_python() via Unescaped $() SubstitutionEPSS 0.6%CVE-2026-80442CRITICALIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.6%CVE-2026-25053CRITICALn8n is Vulnerable to OS Command Injection in Git NodeEPSS 0.6%CVE-2026-55975HIGHH.VIEW HV-500S6 IP Camera OS Command InjectionEPSS 0.6%CVE-2026-20266CRITICALOS Command Injection in the btool Configuration Helper in Splunk AI ToolkitEPSS 0.6%CVE-2026-25722HIGHClaude Code Vulnerable to Command Injection via Directory Change Bypasses Write ProtectionEPSS 0.6%CVE-2026-22179HIGHOpenClaw < 2026.2.22 - Allowlist Bypass via Command Substitution in system.runEPSS 0.6%CVE-2023-47540MEDIUMAn improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 tEPSS 0.6%CVE-2026-72739MEDIUMDokploy: Command Injection via Compose Shell ExecutionEPSS 0.6%CVE-2026-53790CRITICALrsync < 3.5.0 Command Injection via Multiple Code PathsEPSS 0.6%CVE-2024-40587MEDIUMAn improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiVoice EPSS 0.6%CVE-2026-72862CRITICALDokploy: OS Command Injection via dockerImage field in database service deployment functions → HOST RCEEPSS 0.6%CVE-2026-34057HIGHCoolify: Authenticated Remote Code Execution via Command Injection in Database Import Container NameEPSS 0.6%CVE-2026-34035HIGHCoolify: Host RCE via Log Drain secret/env command injectionEPSS 0.6%