Medium severity5.5NVD Advisory· Published Jan 9, 2024· Updated Jun 17, 2026
CVE-2023-50974
CVE-2023-50974
Description
In Appwrite CLI before 3.0.0, when using the login command, the credentials of the Appwrite user are stored in a ~/.appwrite/prefs.json file with 0644 as UNIX permissions. Any user of the local system can access those credentials.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
appwrite-clinpm | < 3.0.0 | 3.0.0 |
appwritePyPI | < 3.0.0 | 3.0.0 |
Affected products
4- cpe:2.3:a:appwrite:command_line_interface:*:*:*:*:*:*:*:*Range: <3.0.0
- Appwrite/CLIdescription
- ghsa-coords2 versions
< 3.0.0+ 1 more
- (no CPE)range: < 3.0.0
- (no CPE)range: < 3.0.0
Patches
Vulnerability mechanics
References
5- gist.github.com/SkypLabs/72ee00ecfa7d1a3494e2d69a24279c1dnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-g777-crp9-m27gghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-50974ghsaADVISORY
- appwrite.io/docs/tooling/command-line/installationnvdProductWEB
- github.com/pypa/advisory-database/tree/main/vulns/appwrite/PYSEC-2024-2.yamlghsaWEB
News mentions
0No linked articles in our index yet.