PT-2026-94397 · Appwrite+1 · Appwrite

·

CVE-2026-89036

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Appwrite versions prior to 2.0.0
Description Authenticated users with functions.write or sites.write permissions can execute arbitrary commands. This occurs because the application uses escapeshellcmd() instead of escapeshellarg() and fails to quote the providerRootDirectory parameter when constructing GNU tar commands. By injecting TAB characters, which survive sanitization and act as argument separators, an attacker can inject arbitrary GNU tar arguments, such as --checkpoint-action=exec, to achieve remote code execution as the builds worker process user.
Recommendations Update Appwrite to version 2.0.0 or later.

Exploit

Fix

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-89036

Affected Products

Appwrite