PT-2026-94397 · Appwrite+1 · Appwrite
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Appwrite versions prior to 2.0.0
Description
Authenticated users with
functions.write or sites.write permissions can execute arbitrary commands. This occurs because the application uses escapeshellcmd() instead of escapeshellarg() and fails to quote the providerRootDirectory parameter when constructing GNU tar commands. By injecting TAB characters, which survive sanitization and act as argument separators, an attacker can inject arbitrary GNU tar arguments, such as --checkpoint-action=exec, to achieve remote code execution as the builds worker process user.Recommendations
Update Appwrite to version 2.0.0 or later.
Exploit
Fix
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Appwrite