VulnSea

CWE-88

CVEs classified under CWE-88, newest first.

118 CVEsRSS

GHSA-vv65-f55v-xm6gHigh
2mo ago

Grackle has command/argument injection in the git worktree executor that enables RCE on provisioned hosts via an unsanitized task branch name (shell:true)

Grackle has command/argument injection in the git worktree executor that enables RCE on provisioned hosts via an unsanitized task branch name (shell:true)

▾ Twilightgrackle-ai · @grackle-ai/runtime-sdkvia GHSA
CVE-2026-49987High· 8.8
2mo ago

repomix Vulnerable to Command Injection (RCE) via `--remote-branch` Argument Injection

repomix Vulnerable to Command Injection (RCE) via `--remote-branch` Argument Injection

▾ Twilightrepomix · repomixEPSS 0.70%via GHSA
GHSA-5vwr-qchf-q4pfMedium
3mo ago

@cyclonedx/cdxgen: Maven project scanning may allow shell command injection through repository-controlled module paths

@cyclonedx/cdxgen: Maven project scanning may allow shell command injection through repository-controlled module paths

▾ Sunlitcyclonedx · @cyclonedx/cdxgenvia GHSA
CVE-2026-50014Medium· 6.4
3mo ago

pnpm: Git Fetch Argument Injection via Lockfile resolution.commit

pnpm: Git Fetch Argument Injection via Lockfile resolution.commit

▾ Sunlitpnpm · pnpmEPSS 0.32%via GHSA
GHSA-74p7-6h78-gw8pHigh
3mo ago

skillctl: argument injection, path traversal in --dest, FIFO/device DoS, hardlink exfiltration, and commit-trailer forgery

skillctl: argument injection, path traversal in --dest, FIFO/device DoS, hardlink exfiltration, and commit-trailer forgery

▾ Twilightskillctl · skillctlvia GHSA
CVE-2026-12530High· 7.3
3mo ago

Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()

Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()

▾ Twilightbedrock-agentcore · bedrock-agentcoreEPSS 0.34%via GHSA
GHSA-r253-r9jw-qg44Critical· 10.0
3mo ago

Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args

Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args

▾ Midnightcrawl4ai · crawl4aivia GHSA
CVE-2026-46529High· 7.8PoC
3mo ago

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execut…

▾ MidnightEPSS 0.41%via NVD
CVE-2026-53694NonePoC
3mo ago

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Nomachine allows Argument Injection.This issue affects Nomachine: before 9.5.7, before 8.23.2.

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Nomachine allows Argument Injection.This issue affects Nomachine: before 9.5.7, before 8.23.2.

▾ TwilightEPSS 0.19%via NVD
CVE-2026-11332High· 7.8
3mo ago

A flaw was found in ansible-core

A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can in…

▾ TwilightRed Hat · ansible-coreEPSS 0.22%via NVD
CVE-2024-52011High· 8.3PoC
3mo ago

launch-editor allows users to open files with line numbers in editor from Node.js

launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, an attacker can execute arbitrary commands on W…

▾ MidnightEPSS 0.51%via NVD
CVE-2026-45570Medium· 6.3
4mo ago

github.com/go-git/go-git: go-git: Shell command injection in SSH transport (CVE-2026-45570)

A flaw was found in go-git, a library used for Git operations. The component responsible for secure shell (SSH) communication does not correctly handle special characters in repository paths. This oversight allows a remote attacker to mani…

▾ SunlitRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.17EPSS 0.43%via CSAF
CVE-2026-42266High· 8.8
4mo ago

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_…

▾ Twilightjupyter · jupyterlabEPSS 0.85%via NVD
CVE-2025-40948Medium· 6.8
4mo ago

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1500 (All versions < V2.17.1), RUGGEDCO…

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1500 (All versions < V2.17.1), RUGGEDCO…

▾ SunlitEPSS 0.40%via NVD
CVE-2026-42284High· 7.5
4mo ago

GitPython: GitPython: Arbitrary code execution via improper validation of clone options (CVE-2026-42284)

A flaw was found in GitPython, a Python library for interacting with Git repositories. A remote attacker could exploit an input validation vulnerability in the `_clone()` function. By crafting a malicious string in the `multi_options` para…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.71%via CSAF
CVE-2026-42215High· 7.5
4mo ago

GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks (CVE-2026-42215)

A flaw was found in GitPython, a Python library used to interact with Git repositories. This vulnerability allows an attacker to achieve arbitrary command execution by providing specially crafted arguments (kwargs) to functions such as Rep…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.90%via CSAF
CVE-2026-6951Critical· 9.8PoC
5mo ago

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the e…

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the e…

▾ Abyssalsimple-git_project · simple-gitEPSS 1.0%via NVD
CVE-2026-40938High· 7.5
5mo ago

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3.4, 1.6.2, 1.9.3, and 1.11.1, the git resolver's revision parameter is passed directly a…

▾ Twilightlinuxfoundation · tekton_pipelinesEPSS 0.90%via NVD
CVE-2026-4145High· 7.8
5mo ago

During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.

During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.

▾ Twilightlenovo · software_fixEPSS 0.21%via NVD
CVE-2026-4786High· 7.1
5mo ago

Mitgation of CVE-2026-4519 was incomplete

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 fo…

▾ TwilightEPSS 0.48%via NVD
CVE-2026-35536Medium· 5.4
5mo ago

tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments (CVE-2026-35536)

A flaw was found in Tornado. A remote attacker could exploit this vulnerability by injecting specially crafted characters into the `domain`, `path`, and `samesite` arguments when setting cookies. This could lead to cookie attribute injecti…

▾ SunlitRed Hat · Red Hat OpenShift AI 2.25EPSS 0.29%via CSAF
CVE-2026-23924Medium· 4.9
6mo ago

Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon

Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon. An attacker capable of invoking Agent 2 can read arbitrary files from running Docker containers by …

▾ Sunlitzabbix · zabbixEPSS 0.23%via NVD
CVE-2026-4519Low· 3.3
6mo ago

The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers

The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to …

▾ Sunlitpython · pythonEPSS 0.39%via NVD
CVE-2025-24293High· 8.1PoC
8mo ago

# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three me…

# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three me…

▾ MidnightEPSS 5.4%via NVD
CVE-2025-61731High· 7.8
8mo ago

Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content

Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config:" directive in a Go source file provides command-line arguments to provide to…

▾ Twilightgolang · goEPSS 0.62%via NVD
CVE-2024-58275None
9mo ago

Easywall 0.3.1 allows authenticated remote command execution via a command injection vulnerability in the /ports-save endpoint that suffers from a parameter injection flaw

Easywall 0.3.1 allows authenticated remote command execution via a command injection vulnerability in the /ports-save endpoint that suffers from a parameter injection flaw. Attackers can inject shell metacharacters to execute arbitrary c…

▾ SunlitEPSS 1.8%via NVD
CVE-2024-51532High· 7.1
1y ago

Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability

Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modificati…

▾ Twilightdell · powerstoreosEPSS 0.27%via NVD
CVE-1999-0113Critical· 10.0PoC
32y ago

Some implementations of rlogin allow root access if given a -froot parameter.

Some implementations of rlogin allow root access if given a -froot parameter.

▾ AbyssalEPSS 17%via NVD
CWE-88 vulnerabilities (CVEs) — page 4 · VulnSea