Falhas do tipo CWE-78
4.669 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2025-41225HIGHVMware vCenter Server authenticated command-execution vulnerabilityEPSS 0.3%CVE-2026-43991HIGHJunoClaw: plugin-shell shell-injection bypass via substring blocklistEPSS 0.3%CVE-2026-35043HIGHBentoML: command injection in cloud deployment setup script (deployment.py)EPSS 0.3%CVE-2026-44465HIGHZed: Zed IDE Arbitrary Code Execution via untrusted repository with poisoned .git/configEPSS 0.3%CVE-2023-20056MEDIUMCisco Access Point Software Denial of Service VulnerabilityEPSS 0.3%CVE-2026-28463HIGHOpenClaw < 2026.2.14 - Arbitrary File Read via Shell Expansion in Safe Bins AllowlistEPSS 0.3%CVE-2026-24154HIGHNVIDIA Jetson Linux has vulnerability in initrd, where an unprivileged attacker with physical access coul inject incorrect command line arguEPSS 0.3%CVE-2024-54012HIGHCommand InjectionEPSS 0.3%CVE-2025-43020MEDIUMPoly Clariti Manager - Multiple Security VulnerabilitiesEPSS 0.3%CVE-2026-57282MEDIUMJenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded into a generated SSH EPSS 0.3%CVE-2026-48703HIGHWarp: Command Injection via Warp code search tool argumentsEPSS 0.3%CVE-2026-46709HIGHTabby: Drag-and-drop path injection still allows RCE via shell command substitution (incomplete fix for CVE-2026-45038)EPSS 0.3%CVE-2023-20050MEDIUMCisco NX-OS Software CLI Command Injection VulnerabilityEPSS 0.3%CVE-2024-39522HIGHJunos OS Evolved: CLI parameter processing issue allows privilege escalationEPSS 0.3%CVE-2024-39520HIGHJunos OS Evolved: CLI parameter processing issue allows privilege escalationEPSS 0.3%CVE-2024-39524HIGHJunos OS Evolved: CLI parameter processing issue allows privilege escalationEPSS 0.3%CVE-2024-39521HIGHJunos OS Evolved: CLI parameter processing issue allows privilege escalationEPSS 0.3%CVE-2024-39523HIGHJunos OS Evolved: CLI parameter processing issue allows privilege escalationEPSS 0.3%CVE-2026-44461HIGHZed: Remote Command Injection via Unquoted Environment Variable Keys (SSH / WSL Remote)EPSS 0.2%CVE-2026-100559HIGHOpenClaw before 2026.8.1 Command Injection via Escaped NewlinesEPSS 0.2%