Command Injection
Also known as:OS Command Injection
Command Injection: Injecting operating system commands into an application that passes input to a shell. The vulnerability usually leads directly to remote code executionRemote Code ExecutionVulnerability or attack that allows code to be executed on a remote target. in the service context.
How it works and where it fits
When an application invokes an external program through a shell and interpolates input into the command line, the shell also interprets that input’s metacharacters. A semicolon, pipe, backticks, or $(...) terminate the intended command and start a second one. A related and frequently overlooked case needs no metacharacters at all: if a program is invoked without an absolute path, a manipulated search path is enough to execute an attacker-supplied file in its place.
Practical security relevance
The most effective protection is to avoid the shell entirely: spawn processes directly, pass arguments as a list, and never assemble them as a string. Where an external call is unavoidable, absolute paths, a sanitised environment, and an allowlist of permitted values belong to the design. Filtering individual special characters is reliably incomplete. Assessment should also cover the blind variant, where no output returns and success shows only through timing or outbound connections.
Related concepts
- Injection AttackInjection AttackManipulates interpreters or applications via injected commands or data.: Manipulates interpreters or applications via injected commands or data.
- Remote Code ExecutionRemote Code ExecutionVulnerability or attack that allows code to be executed on a remote target.: Vulnerability or attack that allows code to be executed on a remote target.
- Input ValidationInput ValidationVerification of input data regarding format, length, type, value range, and validity.: Verification of input data regarding format, length, type, value range, and validity.
- Secure CodingSecure CodingProgramming practices aimed at avoiding common vulnerabilities and misconfigurations.: Programming practices aimed at avoiding common vulnerabilities and misconfigurations.