Falhas do tipo CWE-78
4.668 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2026-44932HIGHindirect remote shell command injection via unsanitized DHCP options in wickedEPSS 0.5%CVE-2025-9997MEDIUMCWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause comEPSS 0.5%CVE-2024-22132HIGHCode Injection vulnerability in SAP IDES SystemsEPSS 0.5%CVE-2026-71312HIGHrclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command ExecutionEPSS 0.5%CVE-2025-65074HIGHOS Command Injection via Path Traversal in WaveStore ServerEPSS 0.5%CVE-2025-47782HIGHmotionEye vulnerable to RCE in add_camera Function Due to unsafe command executionEPSS 0.5%CVE-2025-70828HIGHAn issue in Datart v1.0.0-rc.3 allows attackers to execute arbitrary code via the url parameter in the JDBC configurationEPSS 0.5%CVE-2024-42166CRITICALCommand Injection in ApplicationnameEPSS 0.5%CVE-2026-26982MEDIUMGhostty affected by arbitrary command execution via control characters in paste and drag-and-drop operationsEPSS 0.5%CVE-2024-42167CRITICALCommand Injection in OrganisationnameEPSS 0.5%CVE-2026-62371HIGHKubeEdge: Command Injection in NodeUpgradeJob - RCE on edge nodes via v1alpha2 APIEPSS 0.5%CVE-2020-3171HIGHCisco FXOS and UCS Manager Software Local Management CLI Command Injection VulnerabilityEPSS 0.5%CVE-2025-66572MEDIUMLoaded Commerce 6.6 Client-Side Template Injection (CSTI)EPSS 0.5%CVE-2025-47857MEDIUMA improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in Fortinet FortiWeb CLIEPSS 0.5%CVE-2026-72874HIGHDokploy: Command Injection via Unescaped Git URL in Clone CommandsEPSS 0.5%CVE-2026-72879CRITICALDokploy: Command Injection via Registry Credentials in Swarm UploadEPSS 0.5%CVE-2026-72870HIGHDokploy: Command Injection via Docker Credentials in buildRemoteDockerEPSS 0.5%CVE-2025-64109HIGHCursor CLI Beta: Command Injection via Untrusted MCP ConfigurationEPSS 0.5%CVE-2026-25706HIGHyast2-samba-client: OS command injection via attacker-controlled Organizational Unit (Active Directory-supplied)EPSS 0.5%CVE-2026-25723HIGHClaude Code Vulnerable to Command Injection via Piped sed Command Bypasses File Write RestrictionsEPSS 0.5%