VulnSea

CWE-88

CVEs classified under CWE-88, newest first.

118 CVEsRSS

CVE-2026-68939None
1mo ago

Pyenv provides simple Python version management

Pyenv provides simple Python version management. Prior to 2.8.0, is_version_safe() in libexec/pyenv-version-file-read accepts shell glob metacharacters in .python-version values, and unquoted PYENV_VERSION expansion in libexec/pyenv-vers…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-75913Critical· 9.3
1mo ago

CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool

CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter is passed unvalidated into the git show argv without an --end-of-opt…

▾ Midnightdeepseek-tui · deepseek-tuiEPSS 0.48%via NVD
CVE-2026-75912High· 7.4
1mo ago

CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool that allows attackers to read arbitrary files by injecting git options into the unvalidated rev parameter

CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool that allows attackers to read arbitrary files by injecting git options into the unvalidated rev parameter. Attackers can supply rev values…

▾ Twilightdeepseek-tui · deepseek-tuiEPSS 0.45%via NVD
CVE-2026-52817High
1mo ago

Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems

Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 5.1.0, the shipped assets/sudoers/Debian.sudoers policy allowed the nagios or icinga account to execute /usr/bin/apt-get…

▾ Twilightlinuxfabrik-lib · linuxfabrik-libEPSS 0.18%via NVD
CVE-2026-53790High· 8.1
1mo ago

rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, including the RSYNC_CONNECT_PROG environment …

rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbitrary commands by supplying malicious input through several code paths, including the RSYNC_CONNECT_PROG environment …

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.70%via NVD
CVE-2026-53783High· 8.1
1mo ago

rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to escape enforced directory restrictions by substituting a symlink…

rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows authenticated clients to escape enforced directory restrictions by substituting a symlink…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.49%via NVD
CVE-2026-73624High· 8.1
1mo ago

GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs

GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options passed through kwargs. Attackers can supply the --output argument via the other parameter o…

▾ TwilightRed Hat · Red Hat OpenShift AI 2.25EPSS 0.50%via NVD
CVE-2026-73620High· 8.8
1mo ago

gitpython: GitPython: Arbitrary file overwrite and read via unsafe git option forwarding (CVE-2026-73620)

A flaw was found in GitPython. This vulnerability arises from insufficient guarding of git option forwarding within the `IndexFile.checkout()` and `TagReference.create()` functions. An authenticated attacker can exploit this by passing uns…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.57%via CSAF
CVE-2026-73294Critical· 9.9
1mo ago

Semaphore UI is a web interface for managing DevOps tools

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handling passes an attacker-controlled --upload-pack option to CmdGitClient.GetLastRemoteCommitHash through POST /api/projec…

▾ Midnightsemaphoreui · github.com/semaphoreui/semaphoreEPSS 0.65%via NVD
CVE-2026-66808High· 8.8
1mo ago

Microsoft SharePoint Server Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 2.0%via CVEORG
GHSA-4gmw-gg2m-w46pHigh· 8.1
1mo ago

GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

▾ TwilightGitPython · GitPythonvia GHSA
GHSA-9rj7-rf2p-w77rHigh· 7.5
1mo ago

GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks

GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks

▾ TwilightGitPython · GitPythonvia GHSA
GHSA-jm78-9fvv-mhgrHigh· 8.8
1mo ago

GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)

GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)

▾ TwilightGitPython · GitPythonvia GHSA
GHSA-wvpp-8hx9-p66jHigh· 8.8
1mo ago

GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution

GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution

▾ TwilightGitPython · GitPythonvia GHSA
CVE-2026-71212Medium· 4.4
1mo ago

xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp command-line invocation (xidown/core/scanner.py and downloader.py) by appending the user-provided or scanned URL as a bare trailing positional argument, with no '--' end-of-options m…

xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp command-line invocation (xidown/core/scanner.py and downloader.py) by appending the user-provided or scanned URL as a bare trailing positional argument, with no '--' end-of-options m…

▾ SunlitEPSS 0.16%via NVD
GHSA-p538-c434-8v24Medium· 5.4
1mo ago

GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count

GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count

▾ SunlitGitPython · GitPythonvia GHSA
CVE-2026-67323High· 8.4
1mo ago

GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command exe…

GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command exe…

▾ TwilightGitPython · GitPythonEPSS 1.3%via NVD
CVE-2026-17347High· 7.5
1mo ago

The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name

The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous…

▾ TwilightEPSS 0.72%via NVD
CVE-2026-43698High· 7.8
2mo ago

An injection issue was addressed with improved validation

An injection issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.7. An app may be able to gain root privileges.

▾ Twilightapple · macosEPSS 0.22%via NVD
GHSA-g3hq-hphg-8fhhHigh· 8.8
2mo ago

Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization fixes

Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization fixes

▾ Twilightpheditor · pheditor/pheditorvia GHSA
CVE-2026-16796High· 7.3
2mo ago

AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()

AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()

▾ Twilightbedrock-agentcore · bedrock-agentcoreEPSS 0.73%via GHSA
GHSA-fjr4-x663-mwxcHigh· 8.1
2mo ago

GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)

GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)

▾ TwilightGitPython · GitPythonvia GHSA
GHSA-r9mr-m37c-5fr3High· 8.8
2mo ago

GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution

GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution

▾ TwilightGitPython · GitPythonvia GHSA
CVE-2026-44210Critical· 9.9
2mo ago

kata-containers: Kata Containers: Privilege escalation and information disclosure via command-line argument injection (CVE-2026-44210)

A flaw was found in Kata Containers, an open-source project that provides lightweight virtual machines (VMs) for containers. A user with privileges to create pods can inject malicious command-line arguments into the virtiofsd process, whic…

▾ MidnightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.59%via CSAF
GHSA-956x-8gvw-wg5vHigh· 8.4
2mo ago

GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`

GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`

▾ TwilightGitPython · GitPythonvia GHSA
CVE-2026-52891Critical· 9.9
2mo ago

Wekan is open source kanban built with Meteor

Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied filenames into paths later passed to child_process.exec() for MIME-type detection. Because models/avatars.js and models/…

▾ MidnightEPSS 0.78%via NVD
CVE-2026-61459Critical· 9.8PoC
2mo ago

MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying re…

MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying re…

▾ Abyssalsuyogs · mcp-server-kubernetesEPSS 2.4%via NVD
CVE-2026-54088CriticalPoC
2mo ago

File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)

File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)

▾ Abyssalfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.76%via GHSA
CVE-2026-47829High· 7.8
2mo ago

Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, leading to lo…

Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, leading to lo…

▾ Twilightcloudfoundry · bosh_cliEPSS 0.42%via NVD
CVE-2026-14459High· 8.8PoC
2mo ago

Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection. This issue affects pardus-software: f…

Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection. This issue affects pardus-software: f…

▾ MidnightEPSS 0.21%via NVD
CWE-88 vulnerabilities (CVEs) — page 3 · VulnSea