Falhas do tipo CWE-78
4.669 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2025-15559CRITICALUnauthenticated OS Command Injection in NesterSoft WorkTimeEPSS 0.5%CVE-2020-1734HIGHA flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() wiEPSS 0.5%CVE-2022-22298MEDIUMA improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiIsolator version 1.0.0, FortiIEPSS 0.5%CVE-2026-22902MEDIUMQuNetSwitchEPSS 0.5%CVE-2026-55581HIGHmcp-shell: Secure Mode Allowlist Bypass via Default `/bin/bash` ExecutableEPSS 0.5%CVE-2026-31854HIGHCursor Affected by Arbitrary Code Execution via Prompt Injection and Whitelist BypassEPSS 0.5%CVE-2024-48891MEDIUMAn Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR 7.6.0 throEPSS 0.5%CVE-2022-34437MEDIUMDell PowerScale OneFS, versions 8.2.2-9.3.0, contain an OS command injection vulnerability. A privileged local malicious user could potentiaEPSS 0.5%CVE-2026-20036MEDIUMCisco UCS Manager Software Command Injection VulnerabilityEPSS 0.5%CVE-2026-45632CRITICALDokploy: Schedule Authorization Bypass Enables Host/Server Command ExecutionEPSS 0.5%CVE-2025-27759MEDIUMAn improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiWeb veEPSS 0.4%CVE-2024-5461HIGHCommand or parameter injection via unique embedded switch SNMP commands.EPSS 0.4%CVE-2019-1770MEDIUMCisco NX-OS Software Command Injection VulnerabilityEPSS 0.4%CVE-2023-20022MEDIUMCisco Identity Services Engine Privilege Escalation VulnerabilitiesEPSS 0.4%CVE-2023-20021MEDIUMCisco Identity Services Engine Privilege Escalation VulnerabilitiesEPSS 0.4%CVE-2023-20023MEDIUMCisco Identity Services Engine Privilege Escalation VulnerabilitiesEPSS 0.4%CVE-2026-0309MEDIUMPAN-OS: Authenticated Command Injection in CLI with Luna HSM ConfigurationEPSS 0.4%CVE-2025-36245HIGHIBM InfoSphere Information Server command executionEPSS 0.4%CVE-2026-53534HIGHJabRef CAYW Sublime Text integration permits operating-system command injectionEPSS 0.4%CVE-2026-79916CRITICALMaxKB AWS Bedrock model credential injection leads to remote code executionEPSS 0.4%