Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-89036: Appwrite lets certain users run commands via folder setting
CVE-2026-89036 · published 23 days ago
Summary
In Appwrite versions before 2.0.0, a user who can create or modify functions or sites can trick the system into running additional commands when it builds files. The problem occurs because the software does not correctly protect a folder‑path parameter, so special characters can be added to inject extra instructions. Upgrade to version 2.0.0 or later, or apply the vendor’s patch, to stop this behavior.
What to do
- Update appwrite appwrite to version 2.0.0 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| appwrite | appwrite | < 2.0.0 |
Original advisory text
Appwrite < 2.0.0 Argument Injection via providerRootDirectory Parameter
Appwrite before 2.0.0 contains an argument injection vulnerability that allows authenticated users with functions.write or sites.write permissions to execute arbitrary commands by injecting TAB characters into the providerRootDirectory parameter used to construct GNU tar commands. The application uses escapeshellcmd instead of escapeshellarg and fails to quote the parameter, allowing TAB characters to survive sanitization and be interpreted as argument separators, enabling injection of arbitrary GNU tar arguments such as --checkpoint-action=exec to achieve remote code execution as the builds worker process user.
References
- https://github.com/appwrite/appwrite/releases#release-2.0.0 Vendor Advisory
- https://github.com/appwrite/appwrite/pull/13028 Patch
- https://github.com/appwrite/appwrite/commit/a82dc6e386a6ac7b88e853a1e6fdb59e0b79... Patch
- https://www.vulncheck.com/advisories/appwrite-argument-injection-via-providerroo... Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89036... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-89036 Vendor Advisory
- https://github.com/appwrite/appwrite Product
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.4
Critical
Type
CWE-88Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
Timeline
Published17 Sep 2026
Updated10 Oct 2026
First seen17 Sep 2026
Track software like this
Free during beta