Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-89036: Appwrite lets certain users run commands via folder setting

CVE-2026-89036 · published 23 days ago
Summary

In Appwrite versions before 2.0.0, a user who can create or modify functions or sites can trick the system into running additional commands when it builds files. The problem occurs because the software does not correctly protect a folder‑path parameter, so special characters can be added to inject extra instructions. Upgrade to version 2.0.0 or later, or apply the vendor’s patch, to stop this behavior.

What to do
  • Update appwrite appwrite to version 2.0.0 or later.
Affected software
VendorProductAffected versions
appwrite appwrite < 2.0.0
Original advisory text
Appwrite < 2.0.0 Argument Injection via providerRootDirectory Parameter
Appwrite before 2.0.0 contains an argument injection vulnerability that allows authenticated users with functions.write or sites.write permissions to execute arbitrary commands by injecting TAB characters into the providerRootDirectory parameter used to construct GNU tar commands. The application uses escapeshellcmd instead of escapeshellarg and fails to quote the parameter, allowing TAB characters to survive sanitization and be interpreted as argument separators, enabling injection of arbitrary GNU tar arguments such as --checkpoint-action=exec to achieve remote code execution as the builds worker process user.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.4 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-88Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
Timeline
Published17 Sep 2026
Updated10 Oct 2026
First seen17 Sep 2026
Sources
CVE-2026-89036 · MITRE
Track software like this
Free during beta