Falhas do tipo CWE-78

4.668 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2026-71243HIGHbackmeup (npm) - OS Command Injection via Backup Option ValuesEPSS 0.5%CVE-2023-7338HIGHRuckus Unleashed Authenticated RCE in Gateway ModeEPSS 0.5%CVE-2019-15274MEDIUMCisco TelePresence Collaboration Endpoint Software Command Injection VulnerabilityEPSS 0.5%CVE-2022-35976MEDIUMImproper KubeConfig handling allows arbitrary code executionEPSS 0.5%CVE-2026-82369HIGHInsufficient input sanitization of shell metacharacters in Brocade SANnav before 3.0.1aEPSS 0.5%CVE-2026-34940HIGHKubeAI has an OS Command Injection via Model URL in Ollama Engine startup probe allows arbitrary command execution in model podsEPSS 0.5%CVE-2026-79535MEDIUMmbailey VoiceMode <= 8.10.1 is vulnerable to OS Command Injection. The update_config MCP tool (and the "voicemode config set" CLI) writes a EPSS 0.5%CVE-2026-29783HIGHGitHub Copilot CLI allows for dangerous shell expansion patterns that enable arbitrary command executionEPSS 0.5%CVE-2024-41956HIGHSoft Serve allows arbitrary code execution by crafting git-lfs requestsEPSS 0.5%CVE-2023-41838MEDIUMAn improper neutralization of special elements used in an os command ('os command injection') in FortiManager 7.4.0 and 7.2.0 through 7.2.3 EPSS 0.5%CVE-2026-12545MEDIUMRubygem-hammer_cli: command injection via insecure editor invocationEPSS 0.5%CVE-2025-41281HIGHNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in WateEPSS 0.5%CVE-2026-16856HIGHIBM i is Affected By Multiple Vulnerabilities in Domain Name SystemEPSS 0.5%CVE-2018-19639MEDIUMCode execution if run with command line switch -vEPSS 0.5%CVE-2026-84085HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.5%CVE-2026-53455HIGHBlueprint Studio Git credential helper command injectionEPSS 0.5%CVE-2026-16844HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2026-16842HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2026-82804HIGHApache DolphinScheduler: Command Injection in the Alert Script PluginEPSS 0.5%CVE-2026-14277MEDIUMIBM i Access Client Solutions (ACS) is Affected By Multiple VulnerabilitiesEPSS 0.5%