CWE-88— Argument Injection or Modification
The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.— MITRE CWE catalog
499 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-88page 1 of 10
- CVE-2026-86060CRITICALCVSS 9.8EG 9.8⚠ KEV2026-09-05
RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requi…
- CVE-2026-24061CRITICALCVSS 9.8EG 9.8⚠ KEV2026-01-21
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
- CVE-2020-12641CRITICALCVSS 9.8EG 9.8⚠ KEV2020-05-04
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.
- CVE-2016-10033CRITICALCVSS 9.8EG 9.8⚠ KEV2016-12-30
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sende…
- CVE-2022-36804CRITICALCVSS 8.8EG 9.0⚠ KEV2022-08-25
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8…
- CVE-2024-41710CRITICALCVSS 7.2EG 9.0⚠ KEV2024-08-12
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argum…
- CVE-2026-65770CRITICALCVSS 10.0EG 10.02026-08-20
Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.
- CVE-2026-57572CRITICALCVSS 10.0EG 10.02026-07-06
Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra_args, which flowed into Chromium's launch arguments. An attacker could inject Chromium sw…
- CVE-2026-40281CRITICALCVSS 10.0EG 10.02026-05-06
Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint validates metadata keys for control characters but leaves metadata values unsanitized. A newline character in a metadata…
- CVE-2024-24576CRITICALCVSS 10.0EG 10.02024-04-09
Rust is a programming language. The Rust Security Response WG was notified that the Rust standard library prior to version 1.77.2 did not properly escape arguments when invoking batch files (with the `bat` and `cmd` extensions) on Windows …
- CVE-2023-6269CRITICALCVSS 9.8EG 10.02023-12-05
An argument injection vulnerability has been identified in the administrative web interface of the Atos Unify OpenScape products "Session Border Controller" (SBC) and "Branch", before version V10 R3.4.0, and OpenScape "BCF" before versio…
- CVE-2007-0882HIGHCVSS v2 10.0EG 10.02007-02-12
Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the login program to skip authentication, which allows remote a…
- CVE-2004-0480HIGHCVSS v2 10.0EG 10.02004-12-06
Argument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to execute arbitrary code via a notes: URI that uses a UNC network share pathname to provide an alternate notes.ini configuration file to notes.exe.
- CVE-1999-0113HIGHCVSS v2 10.0EG 10.01994-05-23
Some implementations of rlogin allow root access if given a -froot parameter.
- CVE-2026-84502CRITICALCVSS 9.9EG 9.92026-09-23
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not validated against values that begin with a dash and is stored and passed verbatim to the git SCM module. Because the module …
- CVE-2026-62867CRITICALCVSS 9.9EG 9.92026-08-21
Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage volume configuration leads to argument injection in the constructed filesystem creation…
- CVE-2026-73294CRITICALCVSS 9.9EG 9.92026-08-12
Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handling passes an attacker-controlled --upload-pack option to CmdGitClient.GetLastRemoteCommitHash through POST /api/project/…
- CVE-2026-52891CRITICALCVSS 9.9EG 9.92026-07-15
Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied filenames into paths later passed to child_process.exec() for MIME-type detection. Because models/avatars.js and models/fi…
- CVE-2026-47365CRITICALCVSS 9.9EG 9.92026-06-12
Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account.
- CVE-2026-44210CRITICALCVSS 9.9EG 9.92026-05-26
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Versions prior to 3.31.0 ship with a default configuration that allows pod creators to inje…
- CVE-2026-44450CRITICALCVSS 9.9EG 9.92026-05-26
Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the MCP server creation endpoint validates the command field against an allowlist of binary names but forwards the args array to the child process without any validation. Ev…
- CVE-2024-47553CRITICALCVSS 9.9EG 9.92024-10-08
A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate user input to the ```ssmctl-client``` command. This could allow an authenticated, lowly privileged …
- CVE-2024-3980CRITICALCVSS 9.9EG 9.92024-08-27
The MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that are used in filesystem operations. If exploited the vulnerability allows the attacker to access or modify system files …
- CVE-2024-39930CRITICALCVSS 9.9EG 9.92024-07-04
The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated attackers can exploit this by opening an SSH connection and sending a malicious --split-string…
- CVE-2018-3856CRITICALCVSS 9.9EG 9.92018-08-23
An exploitable vulnerability exists in the smart cameras RTSP configuration of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The device incorrectly handles spaces in the URL field, leading to an arbitrary operating sy…
- CVE-2026-102827CRITICALCVSS 9.8EG 9.82026-09-29
simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin compares parsed option names with literal…
- CVE-2026-54337CRITICALCVSS 9.8EG 9.82026-09-15
Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.14, an argument Injection in the video upload function allows unauthenticated attacker to write/overwrite system files. Version 1.6.14 fixes the issue.
- CVE-2026-71377CRITICALCVSS 9.8EG 9.82026-09-08
Command Argument Injection Vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-4…
- CVE-2026-79675CRITICALCVSS 9.8EG 9.82026-08-25
NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like -agentpath, -javaagent, or…
- CVE-2026-78676CRITICALCVSS 9.8EG 9.82026-08-25
GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlin…
- CVE-2026-16770CRITICALCVSS 9.8EG 9.82026-08-12
PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document. For an HTML string or file source, the constructor collects every <meta name="pdf-webkit-KEY" content="VALUE"> eleme…
- CVE-2026-73240CRITICALCVSS 9.8EG 9.82026-08-12
Specifically crafted inputs may lead to git argument injection in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.
- CVE-2026-61459CRITICALCVSS 9.8EG 9.82026-07-10
MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying reso…
- CVE-2026-40079CRITICALCVSS 9.8EG 9.82026-06-25
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command Injection due to lack of sanitization in the escape_command() function. The escape_command() function at lib/rrd.php is…
- CVE-2026-31230CRITICALCVSS 9.8EG 9.82026-05-12
The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a command-line argument injection vulnerability in its Kubeflow component (robustness_evaluation_fgsm_pytorch.py). The script uses the unsafe eval() function to parse string val…
- CVE-2026-42601CRITICALCVSS 9.8EG 9.82026-05-09
ArchiveBox is an open source self-hosted web archiving system. In versions 0.8.6rc0 and prior, the /add/ endpoint (AddView in core/views.py) accepts a config JSON field that gets merged into the crawl config without validation. This config…
- CVE-2026-6951CRITICALCVSS 9.8EG 9.82026-04-25
Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the equ…
- CVE-2026-22738CRITICALCVSS 9.8EG 9.82026-03-27
In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter expression key. A malicious actor could exploit this to execute arbitrary code. Only applications that use SimpleVe…
- CVE-2026-32304CRITICALCVSS 9.8EG 9.82026-03-13
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to 3.0.14, the create_function(args, code) function passes both parameters directly to the Function constructor without any sanitization, a…
- CVE-2026-27613CRITICALCVSS 9.8EG 9.82026-02-25
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. A vulnerability in versions prior to 2.01 allows unauthenticated remote attackers to bypass the web server's CGI parameter security controls. Depending on the server config…
- CVE-2025-70327CRITICALCVSS 9.8EG 9.82026-02-23
TOTOLINK X5000R v9.1.0cu_2415_B20250515 contains an argument injection vulnerability in the setDiagnosisCfg handler of the /usr/sbin/lighttpd executable. The ip parameter is retrieved via websGetVar and passed to a ping command through Cst…
- CVE-2026-22583CRITICALCVSS 9.8EG 9.82026-01-24
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (CloudPagesUrl module) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud …
- CVE-2026-22582CRITICALCVSS 9.8EG 9.82026-01-24
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (MicrositeUrl module) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud E…
- CVE-2025-52480CRITICALCVSS 9.8EG 9.82025-06-25
Registrator is a GitHub app that automates creation of registration pull requests for julia packages to the General registry. Prior to version 1.9.5, if the clone URL returned by GitHub is malicious (or can be injected using upstream vulne…
- CVE-2024-47516CRITICALCVSS 9.8EG 9.82025-03-26
A vulnerability was found in Pagure. An argument injection in Git during retrieval of the repository history leads to remote code execution on the Pagure instance.
- CVE-2025-21613CRITICALCVSS 9.8EG 9.82025-01-06
go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set…
- CVE-2024-35307CRITICALCVSS 9.8EG 9.82024-06-10
Argument Injection Leading to Remote Code Execution in Realtime Graph Extension, allowing unauthenticated attackers to execute arbitrary code on the server. This issue affects Pandora FMS: from 700 through <777.
- CVE-2024-3817CRITICALCVSS 9.8EG 9.82024-04-17
HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This vulnerability does not affect the go-getter/v2 branch and package.
- CVE-2024-23731CRITICALCVSS 9.8EG 9.82024-01-21
The OpenAPI loader in Embedchain before 0.1.57 allows attackers to execute arbitrary code, related to the openapi.py yaml.load function argument.
- CVE-2023-33378CRITICALCVSS 9.8EG 9.82023-08-04
Connected IO v2.1.0 and prior has an argument injection vulnerability in its AT command message in its communication protocol, enabling attackers to execute arbitrary OS commands on devices.
Map vulnerabilities like CWE-88 to your infrastructure
EchelonGraph correlates every CVE — across CWE-88 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →