CWE-88— Argument Injection or Modification
The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.— MITRE CWE catalog
499 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-88page 4 of 10
- CVE-2021-42561HIGHCVSS 8.8EG 8.82022-01-12
An issue was discovered in CALDERA 2.8.1. When activated, the Human plugin passes the unsanitized name parameter to a python "os.system" function. This allows attackers to use shell metacharacters (e.g., backticks "``" or dollar parenthesi…
- CVE-2021-41146HIGHCVSS 8.8EG 8.82021-10-21
qutebrowser is an open source keyboard-focused browser with a minimal GUI. Starting with qutebrowser v1.7.0, the Windows installer for qutebrowser registers a `qutebrowserurl:` URL handler. With certain applications, opening a specially cr…
- CVE-2021-38112HIGHCVSS 8.8EG 8.82021-09-22
In the Amazon AWS WorkSpaces client 3.0.10 through 3.1.8 on Windows, argument injection in the workspaces:// URI handler can lead to remote code execution because of the Chromium Embedded Framework (CEF) --gpu-launcher argument. This is fi…
- CVE-2021-36122HIGHCVSS 8.8EG 8.82021-07-13
An issue was discovered in Echo ShareCare 8.15.5. The UnzipFile feature in Access/EligFeedParse_Sup/UnzipFile_Upd.cfm is susceptible to a command argument injection vulnerability when processing remote input in the zippass parameter from a…
- CVE-2021-24002HIGHCVSS 8.8EG 8.82021-06-24
When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been interpreted as such and allowed arbitrary commands to be sent to the FTP server. This vulnerability affects Firefox ESR < 7…
- CVE-2021-1531HIGHCVSS 8.8EG 8.82021-05-22
A vulnerability in the web UI of Cisco Modeling Labs could allow an authenticated, remote attacker to execute arbitrary commands with the privileges of the web application on the underlying operating system of an affected Cisco Modeling La…
- CVE-2021-29472HIGHCVSS 8.8EG 8.82021-04-27
Composer is a dependency manager for PHP. URLs for Mercurial repositories in the root composer.json and package source download URLs are not sanitized correctly. Specifically crafted URL values allow code to be executed in the HgDriver if …
- CVE-2021-27201HIGHCVSS 8.8EG 8.82021-02-15
Endian Firewall Community (aka EFW) 3.3.2 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in a backup comment.
- CVE-2020-35576HIGHCVSS 8.8EG 8.82021-01-26
A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216 allows authenticated users to execute arbitrary code as root via shell metacharacters, a different vulnerability than …
- CVE-2020-19664HIGHCVSS 8.8EG 8.82020-12-31
DrayTek Vigor2960 1.5.1 allows remote command execution via shell metacharacters in a toLogin2FA action to mainfunction.cgi.
- CVE-2020-25268HIGHCVSS 8.8EG 8.82020-11-10
Remote Code Execution can occur via the external news feed in ILIAS 6.4 because of incorrect parameter sanitization for Magpie RSS data.
- CVE-2020-13699HIGHCVSS 8.8EG 8.82020-07-29
TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers. A malicious website could launch TeamViewer with arbitrary parameters, as demonstrated by a teamviewer10: --play URL. An attacker could force a v…
- CVE-2020-5546HIGHCVSS 8.8EG 8.82020-03-16
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier allows an atta…
- CVE-2020-6799HIGHCVSS 8.8EG 8.82020-03-02
Command line arguments could have been injected during Firefox invocation as a shell handler for certain unsupported file types. This required Firefox to be configured as the default handler for a given file type and for a file downloaded …
- CVE-2019-11751HIGHCVSS 8.8EG 8.82019-09-27
Logging-related command line parameters are not properly sanitized when Firefox is launched by another program, such as when a user clicks on malicious links in a chat application. This can be used to write a log file to an arbitrary locat…
- CVE-2019-15498HIGHCVSS 8.8EG 8.82019-08-23
cgi-bin/cmh/webcam.sh in Vera Edge Home Controller 1.7.4452 allows remote unauthenticated users to execute arbitrary OS commands via --output argument injection in the username parameter to /cgi-bin/cmh/webcam.sh.
- CVE-2019-13475HIGHCVSS 8.8EG 8.82019-07-09
In MobaXterm 11.1, the mobaxterm: URI handler has an argument injection vulnerability that allows remote attackers to execute arbitrary commands when the user visits a specially crafted URL. Based on the available command-line arguments of…
- CVE-2019-11582HIGHCVSS 8.8EG 8.82019-06-14
An argument injection vulnerability in Atlassian Sourcetree for Windows's URI handlers, in all versions prior to 3.1.3, allows remote attackers to gain remote code execution through the use of a crafted URI.
- CVE-2019-3931HIGHCVSS 8.8EG 8.82019-04-30
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to argumention injection to the curl binary via crafted HTTP requests to return.cgi. A remote, authenticated attacker can use this vulnerability to uploa…
- CVE-2018-20234HIGHCVSS 8.8EG 8.82019-03-08
There was an argument injection vulnerability in Atlassian Sourcetree for macOS from version 1.2 before version 3.1.1 via filenames in Mercurial repositories. A remote attacker with permission to commit to a Mercurial repository linked in …
- CVE-2018-0345HIGHCVSS 8.8EG 8.82018-07-18
A vulnerability in the configuration and management database of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to execute arbitrary commands with the privileges of the vmanage user in the configuration management s…
- CVE-2022-40677HIGHCVSS 7.2EG 8.82023-02-16
A improper neutralization of argument delimiters in a command ('argument injection') in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 throu…
- CVE-2022-36322HIGHCVSS 5.4EG 8.82022-07-20
In JetBrains TeamCity before 2022.04.2 build parameter injection was possible
- CVE-2026-55887HIGHCVSS 8.7EG 8.72026-06-18
MCP Gateway allows easy and secure running and deployment of MCP servers. From 0.21.0 until 0.42.2, Docker MCP Gateway YAML-unmarshalled the attacker-controlled io.docker.server.metadata OCI image label into the broad catalog.Server struct…
- CVE-2024-58275HIGHCVSS 8.7EG 8.72025-12-04
Easywall 0.3.1 allows authenticated remote command execution via a command injection vulnerability in the /ports-save endpoint that suffers from a parameter injection flaw. Attackers can inject shell metacharacters to execute arbitrary com…
- CVE-2026-8044HIGHCVSS 8.6EG 8.62026-09-09
CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability exists that could cause remote code execution by an attacker with a privileged account when malicious arguments are provided as backup…
- CVE-2025-12613HIGHCVSS 8.6EG 8.62025-11-10
Versions of the package cloudinary before 2.7.0 are vulnerable to Arbitrary Argument Injection due to improper parsing of parameter values containing an ampersand. An attacker can inject additional, unintended parameters. This could lead t…
- CVE-2025-47421HIGHCVSS 8.6EG 8.62025-09-03
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in CRESTRON TOUCHSCREENS x70 allows Argument Injection.This issue affects TOUCHSCREENS x70: from 3.001.0031.001 through 3.001.0034.001. A spe…
- CVE-2025-48385HIGHCVSS 8.6EG 8.62025-07-08
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When cloning a repository Git knows to optionally fetch a bundle adverti…
- CVE-2024-22182HIGHCVSS 8.6EG 8.62024-03-01
A remote, unauthenticated attacker may be able to send crafted messages to the web server of the Commend WS203VICM causing the system to restart, interrupting service.
- CVE-2020-7769HIGHCVSS 8.6EG 8.62020-11-12
This affects the package nodemailer before 6.4.16. Use of crafted recipient email addresses may result in arbitrary command flag injection in sendmail transport for sending mails.
- CVE-2026-93699HIGHCVSS 8.5EG 8.52026-10-08
Argument injection in WP Toolkit for cPanel allows local users to execute arbitrary code as other accounts on the same server.
- CVE-2026-87687HIGHCVSS 8.5EG 8.52026-10-08
An authorization and input validation vulnerability exists in Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user with restricted privileges in one Virtual Fabric can exploit this issue by submitting…
- CVE-2026-86035HIGHCVSS 8.5EG 8.52026-09-29
Weblate is a web-based continuous localization platform used to manage software translations. Weblate 4.11.1 through 2026.7.1 contains an argument-injection vulnerability in its Mercurial backend. Repository filenames beginning with - coul…
- CVE-2026-3515HIGHCVSS 8.5EG 8.52026-05-24
A vulnerability in the `GitHubRepository` block of the `prefect-github` integration in Prefect version 3.6.18 allows an attacker to inject arbitrary git command-line options via the `reference` field. The `reference` field is concatenated …
- CVE-2026-40938HIGHCVSS 8.5EG 8.52026-04-21
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the git resolver's revision parameter is passed directly as …
- CVE-2025-46835HIGHCVSS 8.5EG 8.52025-07-10
Git GUI allows you to use the Git source control management tools via a GUI. When a user clones an untrusted repository and is tricked into editing a file located in a maliciously named directory in the repository, then Git GUI can create …
- CVE-2019-6453HIGHCVSS 8.1EG 8.52019-02-18
mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers. The attacker can specify an irc:// URI that loads an arbitrary .ini file from a UNC share pathname. Exploitation depends on …
- CVE-2026-87667HIGHCVSS 8.4EG 8.42026-10-08
An argument injection vulnerability exists in the configuration management command-line utility of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When executing configuration viewing commands with search pattern filt…
- CVE-2026-100369HIGHCVSS 8.4EG 8.42026-09-25
CliInvoke and its formerly named `AlastairLundy.CliInvoke` package are .NET libraries for invoking command-line programs and wrapping executable processes. `CliInvoke` versions 2.0.0 through 2.8.4, 2.9.0 through 2.9.3, 2.10.0 through 2.10.…
- CVE-2026-87794HIGHCVSS 8.4EG 8.42026-09-09
bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combined …
- CVE-2026-80427HIGHCVSS 8.4EG 8.42026-08-26
bestzip builds the argument list for the system zip utility without separating options from operands. The destination archive path and the caller-supplied source paths are passed to the child process with no -- delimiter between them, so a…
- CVE-2026-40113HIGHCVSS 8.4EG 8.42026-04-09
PraisonAI is a multi-agent teams system. Prior to 4.5.128, deploy.py constructs a single comma-delimited string for the gcloud run deploy --set-env-vars argument by directly interpolating openai_model, openai_key, and openai_base without v…
- CVE-2025-43730HIGHCVSS 8.4EG 8.42025-08-27
Dell ThinOS 10, versions prior to 2508_10.0127, contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A local unauthenticated user could potentially exploit this vulnerability leading…
- CVE-2024-32462HIGHCVSS 8.4EG 8.42024-04-18
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. in versions before 1.10.9, 1.12.9, 1.14.6, and 1.15.8, a malicious or compromised Flatpak app could execute arbitrary code outside its san…
- CVE-2025-59489HIGHCVSS 7.4EG 8.42025-10-03
Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the…
- CVE-2024-52011HIGHCVSS 8.3EG 8.32026-06-01
launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, an attacker can execute arbitrary commands on Win…
- CVE-2026-39884HIGHCVSS 8.3EG 8.32026-04-15
mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Versions 3.4.0 and prior contain an argument injection vulnerability in the port_forward tool in src/tools/port_forward.ts, where a kubectl command…
- CVE-2022-24828HIGHCVSS 8.3EG 8.32022-04-13
Composer is a dependency manager for the PHP programming language. Integrators using Composer code to call `VcsDriver::getFileContent` can have a code injection vulnerability if the user can control the `$file` or `$identifier` argument. T…
- CVE-2026-47829HIGHCVSS 7.8EG 8.32026-07-09
Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, leading to loca…
Map vulnerabilities like CWE-88 to your infrastructure
EchelonGraph correlates every CVE — across CWE-88 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →