CWE-88— Argument Injection or Modification
The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.— MITRE CWE catalog
499 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-88page 2 of 10
- CVE-2023-33376CRITICALCVSS 9.8EG 9.82023-08-04
Connected IO v2.1.0 and prior has an argument injection vulnerability in its iptables command message in its communication protocol, enabling attackers to execute arbitrary OS commands on devices.
- CVE-2023-29405CRITICALCVSS 9.8EG 9.82023-06-08
The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code. This is can by triggered by linker flags, sp…
- CVE-2022-47926CRITICALCVSS 9.8EG 9.82022-12-22
AyaCMS 3.1.2 is vulnerable to file deletion via /aya/module/admin/fst_del.inc.php
- CVE-2022-45062CRITICALCVSS 9.8EG 9.82022-11-09
In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.
- CVE-2022-42968CRITICALCVSS 9.8EG 9.82022-10-16
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled.
- CVE-2022-24437CRITICALCVSS 9.8EG 9.82022-05-01
The package git-pull-or-clone before 2.0.2 are vulnerable to Command Injection due to the use of the --upload-pack feature of git which is also supported for git clone. The source includes the use of the secure child process API spawn(). H…
- CVE-2021-43736CRITICALCVSS 9.8EG 9.82022-03-23
CmsWing CMS 1.3.7 is affected by a Remote Code Execution (RCE) vulnerability via parameter: log rule
- CVE-2022-23221CRITICALCVSS 9.8EG 9.82022-01-19
H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT substring, a different vulnerability than CVE-2021-4239…
- CVE-2021-37040CRITICALCVSS 9.8EG 9.82021-12-08
There is a Parameter injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause privilege escalation of files after CIFS share mounting.
- CVE-2021-31698CRITICALCVSS 9.8EG 9.82021-08-12
Quectel EG25-G devices through 202006130814 allow executing arbitrary code remotely by using an AT command to place shell metacharacters in quectel_handle_fumo_cfg input in atfwd_daemon.
- CVE-2021-33564CRITICALCVSS 9.8EG 9.82021-05-29
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write to arbitrary files via a crafted URL when the verify_url option is disabled. This may lead to code execution. The prob…
- CVE-2021-31909CRITICALCVSS 9.8EG 9.82021-05-11
In JetBrains TeamCity before 2020.2.3, argument injection leading to remote code execution was possible.
- CVE-2020-28026CRITICALCVSS 9.8EG 9.82021-05-06
Exim 4 before 4.94.2 has Improper Neutralization of Line Delimiters, relevant in non-default configurations that enable Delivery Status Notification (DSN). Certain uses of ORCPT= can place a newline into a spool header file, and indirectly…
- CVE-2021-24030CRITICALCVSS 9.8EG 9.82021-03-10
The fbgames protocol handler registered as part of Facebook Gameroom does not properly quote arguments passed to the executable. That allows a malicious URL to cause code execution. This issue affects versions prior to v1.26.0.
- CVE-2020-21224CRITICALCVSS 9.8EG 9.82021-02-22
A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0. A remote attacker can send a malicious login packet to the control server
- CVE-2021-26937CRITICALCVSS 9.8EG 9.82021-02-09
encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly have unspecified other impact via a crafted UTF-8 character sequence.
- CVE-2021-3401CRITICALCVSS 9.8EG 9.82021-02-04
Bitcoin Core before 0.19.0 might allow remote attackers to execute arbitrary code when another application unsafely passes the -platformpluginpath argument to the bitcoin-qt program, as demonstrated by an x-scheme-handler/bitcoin handler f…
- CVE-2020-25494CRITICALCVSS 9.8EG 9.82020-12-18
Xinuos (formerly SCO) Openserver v5 and v6 allows attackers to execute arbitrary commands via shell metacharacters in outputform or toclevels parameter to cgi-bin/printbook.
- CVE-2020-5648CRITICALCVSS 9.8EG 9.82020-11-06
Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT1455-QTBDE CoreOS version "05.65.00.BD" and earlier, GT1450-QM…
- CVE-2020-15692CRITICALCVSS 9.8EG 9.82020-08-14
In Nim 1.2.4, the standard library browsers mishandles the URL argument to browsers.openDefaultBrowser. This argument can be a local file path that will be opened in the default explorer. An attacker can pass one argument to the underlying…
- CVE-2020-5599CRITICALCVSS 9.8EG 9.82020-07-07
TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains an improper neutralization of argument delimiters in a command…
- CVE-2019-12148CRITICALCVSS 9.8EG 9.82019-10-22
The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to an authentication bypass via an argument injection vulnerability involving special characters in the username field. Upon successful exploitation, a r…
- CVE-2019-12147CRITICALCVSS 9.8EG 9.82019-10-22
The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to Argument Injection via special characters in the username field. Upon successful exploitation, a remote unauthenticated user can create a local system…
- CVE-2019-10746CRITICALCVSS 9.8EG 9.82019-08-23
mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
- CVE-2019-9794CRITICALCVSS 9.8EG 9.82019-04-26
A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs. This could be used to retrieve and execute files whose location is supplied through thes…
- CVE-2019-3463CRITICALCVSS 9.8EG 9.82019-02-06
Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations, resulting in the execution of arbitrary shell commands.
- CVE-2018-17456CRITICALCVSS 9.8EG 9.82018-10-06
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git clone" of a superproject if a .gitmodule…
- CVE-2018-13385CRITICALCVSS 9.8EG 9.82018-07-24
There was an argument injection vulnerability in Sourcetree for macOS via filenames in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for macOS is able to exploit this issue to …
- CVE-2018-10992CRITICALCVSS 9.8EG 9.82018-05-11
lilypond-invoke-editor in LilyPond 2.19.80 does not validate strings before launching the program specified by the BROWSER environment variable, which allows remote attackers to conduct argument-injection attacks via a crafted URL, as demo…
- CVE-2017-1001003CRITICALCVSS 9.8EG 9.82017-11-27
math.js before 3.17.0 had an issue where private properties such as a constructor could be replaced by using unicode characters when creating an object.
- CVE-2022-28391CRITICALCVSS 8.8EG 9.82022-04-03
BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors.
- CVE-2020-7808CRITICALCVSS 8.7EG 9.82020-05-21
In RAONWIZ K Upload v2018.0.2.51 and prior, automatic update processing without integrity check on update module(web.js) allows an attacker to modify arguments which causes downloading a random DLL and injection on it.
- CVE-2026-43941CRITICALCVSS 9.6EG 9.62026-05-08
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, Electerm's terminal hyperlink handler passes any URL clicked in the terminal directly to shell.openExternal without any…
- CVE-2026-87900CRITICALCVSS 9.4EG 9.42026-09-23
Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.
- CVE-2026-54501CRITICALCVSS 9.4EG 9.42026-09-17
Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted instance. From 1.15.0 until 1.22.8, Browsertrix improperly sanitizes Git URLs specified as Custom…
- CVE-2026-2298CRITICALCVSS 9.4EG 9.42026-03-23
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before Janu…
- CVE-2025-49008CRITICALCVSS 9.4EG 9.42025-06-05
Atheos is a self-hosted browser-based cloud integrated development environment. Prior to version 6.0.4, improper use of `escapeshellcmd()` in `/components/codegit/traits/execute.php` allows argument injection, leading to arbitrary command …
- CVE-2026-54088CRITICALCVSS 9.3EG 9.32026-06-25
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, the Hook Authentication feature in File Browser allows administrators to delegate log…
- CVE-2021-21386CRITICALCVSS 9.3EG 9.32021-03-24
APKLeaks is an open-source project for scanning APK file for URIs, endpoints & secrets. APKLeaks prior to v2.0.3 allows remote attackers to execute arbitrary OS commands via package name inside application manifest. An attacker could inclu…
- CVE-2026-107510CRITICALCVSS 9.1EG 9.12026-10-08
An authenticated high privilege user can inject arguments in troubleshooting commands resulting in privilege escalation.
- CVE-2026-100714CRITICALCVSS 9.1EG 9.12026-09-26
Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings hardened in GHSA-33mp, the field has no string_regexp or required_otp guard, and its value is concatenated unescaped int…
- CVE-2026-40047CRITICALCVSS 9.1EG 9.12026-07-06
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling component. The camel-docling component invokes the external `docling` command-line tool by assembling an argument lis…
- CVE-2026-44449CRITICALCVSS 9.1EG 9.12026-05-26
Lumiverse is a full-featured AI chat application. Prior to 0.9.7, when the primary toSmbPath(fullPath) call throws, the method falls back to a dirname/basename split and only validates the directory prefix. The basename is concatenated dir…
- CVE-2026-45158CRITICALCVSS 9.1EG 9.12026-05-13
OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsanitized user input is passed to the DHCP configuration of the configured interface, which is processed by a shell script, allowing remote code execution as roo…
- CVE-2026-44193CRITICALCVSS 9.1EG 9.12026-05-13
OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the XMLRPC method opnsense.restore_config_section fails to sanitize user supplied input leading to Remote Code Execution. This vulnerability is fixed in 26.1.7.
- CVE-2026-35033CRITICALCVSS 9.1EG 9.12026-04-14
Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file read vulnerability via ffmpeg argument injection through the StreamOptions query parameter parsing mechanism. The Pars…
- CVE-2026-24126CRITICALCVSS 9.1EG 9.12026-02-19
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to `ssh-add`. Version 5.16.0 fixes the issue. …
- CVE-2025-59937CRITICALCVSS 9.1EG 9.12025-09-29
go-mail is a comprehensive library for sending mails with Go. In versions 0.7.0 and below, due to incorrect handling of the mail.Address values when a sender- or recipient address is passed to the corresponding MAIL FROM or RCPT TO command…
- CVE-2025-32931CRITICALCVSS 9.1EG 9.12025-04-14
DevDojo Voyager 1.4.0 through 1.8.0, when Laravel 8 or later is used, allows authenticated administrators to execute arbitrary OS commands via a specific php artisan command.
- CVE-2024-11633CRITICALCVSS 9.1EG 9.12024-12-10
Argument injection in Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution
Map vulnerabilities like CWE-88 to your infrastructure
EchelonGraph correlates every CVE — across CWE-88 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →