Falhas do tipo CWE-78
4.669 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2022-26868MEDIUMDell EMC PowerStore versions 2.0.0.x, 2.0.1.x, and 2.1.0.x are vulnerable to a command injection flaw. An authenticated attacker could potenEPSS 0.4%CVE-2026-45393HIGHLocal privilege escalation to SYSTEM in Cribl Edge for WindowsEPSS 0.4%CVE-2025-50974MEDIUMThe Calamaris log exporter CGI (/cgi-bin/logs.cgi/calamaris.dat) in IPFire 2.29 does not properly sanitize user-supplied input before incorpEPSS 0.4%CVE-2026-8654HIGHImproper input validation in Delphix Continuous Data connectors allows an authenticated user to execute arbitrary operating system commands EPSS 0.4%CVE-2026-27955MEDIUMCoolify: Command Injection via Single-Quote Breakout in `executeInDocker()`EPSS 0.4%CVE-2026-34955HIGHPraisonAI: Sandbox Escape via shell=True and Bypassable Blocklist in SubprocessSandboxEPSS 0.4%CVE-2025-67037HIGHLantronix EDS5000, G520, and X300 OS Command InjectionEPSS 0.4%CVE-2025-67036HIGHLantronix EDS5000, G520, and X300 OS Command InjectionEPSS 0.4%CVE-2026-79766CRITICALTermix: OS command injection in ACME/Let's Encrypt certificate-request handler via admin-controlled domain/emailEPSS 0.4%CVE-2025-3189MEDIUMStored Cross-Site Scripting (XSS) in DoWISPEPSS 0.4%CVE-2026-102422CRITICALshell-quote `quote()` command injection via a line terminator in a token after a `{ comment }` tokenEPSS 0.4%CVE-2026-84256HIGHAn argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to exEPSS 0.4%CVE-2025-10239HIGHUnintended command execution via troubleshooting scripts in Progress FlowmonEPSS 0.4%CVE-2025-43908MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 releasEPSS 0.4%CVE-2024-10896MEDIUMLogo Slider < 4.5.0 - Contributor+ Stored XSSEPSS 0.4%CVE-2026-85439HIGHMOOS-IvP through 24.8.1 alogsplit Command Injection via Input PathnameEPSS 0.4%CVE-2020-3459MEDIUMCisco FXOS Software for Firepower 4100/9300 Series Command Injection VulnerabilityEPSS 0.4%CVE-2025-70039CRITICALAn issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linagora Twake v2023.Q1.1EPSS 0.4%CVE-2021-1370HIGHCisco IOS XR Software for Cisco 8000 Series Routers and Network Convergence System 540 Series Routers Privilege Escalation VulnerabilityEPSS 0.4%CVE-2026-33030HIGHNginx UI: Unencrypted Storage of DNS API Tokens and ACME Private KeysEPSS 0.4%