Falhas do tipo CWE-78
4.669 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2026-90444HIGHOS Command Injection in MalcolmEPSS 0.3%CVE-2026-100599HIGHOpenClaw 2026.5.1 before 2026.7.1 Remote Code Execution via googlemeet.chromeEPSS 0.3%CVE-2025-24938HIGHInsufficient Validation of Input while user creationEPSS 0.3%CVE-2026-15069MEDIUMMultiple Vulnerabilities in IBM Engineering AI hub.EPSS 0.3%CVE-2026-45562HIGHFreePBX: Authenticated Remote Code Execution in FreePBX Music on Hold (MoH) ModuleEPSS 0.3%CVE-2021-34728HIGHCisco IOS XR Software Authenticated User Privilege Escalation VulnerabilitiesEPSS 0.3%CVE-2025-43875HIGHiSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, iSTAR Edge G2 - Authenticated web application command injection - getOptionsInfoEPSS 0.3%CVE-2026-23920HIGHHost and event action script regex validation can be bypassed in certain situations, leading to potential command injectionEPSS 0.3%CVE-2026-61438HIGHPraisonAI before 4.6.78 Remote Code Execution via Broken AST SandboxEPSS 0.3%CVE-2026-76226MEDIUMRenovate 43.65.0 before 43.102.11 Remote Code Execution via lockFileMaintenanceEPSS 0.3%CVE-2021-3459MEDIUMA privilege escalation vulnerability was reported in the MM1000 device configuration web server, which could allow privileged shell access aEPSS 0.3%CVE-2025-0636HIGHArbitrary Code Execution vulnerability in Ericsson RAN Compute and Site ControllerEPSS 0.3%CVE-2026-34714CRITICALVim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr}EPSS 0.3%CVE-2025-43876HIGHiSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, iSTAR Edge G2 - Authenticated web application command injection - get8021xSettingsEPSS 0.3%CVE-2022-43867HIGHIBM Spectrum Scale command executionEPSS 0.3%CVE-2025-43873HIGHiSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, iSTAR Edge G2 - Authenticated web application command injection - setFaultDebounceEPSS 0.3%CVE-2026-100292HIGHImproper neutralization of special elements used in an OS command ('OS command injection') in Anjvision YSSD-RTMP-H5EPSS 0.3%CVE-2025-22606HIGHCoolify Command Injection Vulnerability in Project NameEPSS 0.3%CVE-2021-21526MEDIUMDell PowerScale OneFS 8.1.0 - 9.1.0 contains a privilege escalation in SmartLock compliance mode that may allow compadmin to execute arbitraEPSS 0.3%CVE-2025-25269HIGHLocal Privilege Escalation via Unauthenticated Command InjectionEPSS 0.3%