VYPR

CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

BaseDraft

Description

The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-137 · CAPEC-174 · CAPEC-41 · CAPEC-460 · CAPEC-88

CVEs mapped to this weakness (466)

page 7 of 24
  • CVE-2025-46835HigJul 10, 2025
    risk 0.55cvss 8.5epss 0.01

    Git GUI allows you to use the Git source control management tools via a GUI. When a user clones an untrusted repository and is tricked into editing a file located in a maliciously named directory in the repository, then Git GUI can create and overwrite files for which the user…

  • CVE-2020-5792HigOct 20, 2020
    risk 0.55cvss 7.2epss 0.59

    Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user to write to arbitrary files and ultimately execute code with the privileges of the apache user.

  • CVE-2026-54501CriSep 17, 2026
    risk 0.54cvss —epss 0.01

    Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted instance. From 1.15.0 until 1.22.8, Browsertrix improperly sanitizes Git URLs specified as Custom Behaviors, allowing command injection…

  • CVE-2025-49008CriJun 5, 2025
    risk 0.54cvss —epss 0.01

    Atheos is a self-hosted browser-based cloud integrated development environment. Prior to version 6.0.4, improper use of `escapeshellcmd()` in `/components/codegit/traits/execute.php` allows argument injection, leading to arbitrary command execution. Atheos administrators and…

  • CVE-2021-21386CriMar 24, 2021
    risk 0.54cvss 9.3epss 0.02

    APKLeaks is an open-source project for scanning APK file for URIs, endpoints & secrets. APKLeaks prior to v2.0.3 allows remote attackers to execute arbitrary OS commands via package name inside application manifest. An attacker could include arguments that allow unintended…

  • CVE-2026-75913CriAug 18, 2026
    risk 0.53cvss 9.3epss 0.00

    CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter is passed unvalidated into the git show argv without an --end-of-options sentinel, so a value beginning with…

  • CVE-2026-41013HigJun 1, 2026
    risk 0.53cvss 8.1epss 0.00

    Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged CF space developer to inject arbitrary kernel CIFS mount options via bypassing the mount-option allowlist, enabling privilege escalation and security control…

  • CVE-2026-43893HigMay 11, 2026
    risk 0.53cvss 8.2epss 0.00

    exiftool-vendored provides cross-platform Node.js access to ExifTool. Prior to 35.19.0, exiftool-vendored starts ExifTool in -stay_open True -@ - mode, where arguments are read from stdin one per line. In affected versions, several caller-supplied strings were interpolated into…

  • CVE-2024-43402HigSep 4, 2024
    risk 0.53cvss 8.1epss 0.01

    Rust is a programming language. The fix for CVE-2024-24576, where `std::process::Command` incorrectly escaped arguments when invoking batch files on Windows, was incomplete. Prior to Rust version 1.81.0, it was possible to bypass the fix when the batch file name had trailing…

  • CVE-2021-41316HigSep 17, 2021
    risk 0.53cvss 8.1epss 0.01

    The Device42 Main Appliance before 17.05.01 does not sanitize user input in its Nmap Discovery utility. An attacker (with permissions to add or edit jobs run by this utility) can inject an extra argument to overwrite arbitrary files as the root user on the Remote Collector.

  • CVE-2021-34718HigSep 9, 2021
    risk 0.53cvss 8.1epss 0.02

    A vulnerability in the SSH Server process of Cisco IOS XR Software could allow an authenticated, remote attacker to overwrite and read arbitrary files on the local device. This vulnerability is due to insufficient input validation of arguments that are supplied by the user for a…

  • CVE-2021-29461HigApr 20, 2021
    risk 0.53cvss 8.1epss 0.02

    Discord Recon Server is a bot that allows one to do one's reconnaissance process from one's Discord. A vulnerability in Discord Recon Server prior to 0.0.3 could be exploited to read internal files from the system and write files into the system resulting in remote code…

  • CVE-2018-13386HigJul 24, 2018
    risk 0.53cvss 8.1epss 0.02

    There was an argument injection vulnerability in Sourcetree for Windows via filenames in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on the system.…

  • CVE-2026-40047CriJul 6, 2026
    risk 0.52cvss 9.1epss 0.02

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling component. The camel-docling component invokes the external `docling` command-line tool by assembling an argument list in DoclingProducer and executing it…

  • CVE-2026-45158CriMay 13, 2026
    risk 0.52cvss 9.1epss 0.01

    OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsanitized user input is passed to the DHCP configuration of the configured interface, which is processed by a shell script, allowing remote code execution as root on the underlying operating system.…

  • CVE-2026-44193CriMay 13, 2026
    risk 0.52cvss 9.1epss 0.01

    OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the XMLRPC method opnsense.restore_config_section fails to sanitize user supplied input leading to Remote Code Execution. This vulnerability is fixed in 26.1.7.

  • CVE-2026-35033CriApr 14, 2026
    risk 0.52cvss 9.1epss 0.00

    Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file read vulnerability via ffmpeg argument injection through the StreamOptions query parameter parsing mechanism. The ParseStreamOptions method in…

  • CVE-2025-59937CriSep 29, 2025
    risk 0.52cvss 9.1epss 0.01

    go-mail is a comprehensive library for sending mails with Go. In versions 0.7.0 and below, due to incorrect handling of the mail.Address values when a sender- or recipient address is passed to the corresponding MAIL FROM or RCPT TO commands of the SMTP client, there is a…

  • CVE-2024-52301HigNov 12, 2024
    risk 0.52cvss 7.5epss 0.45

    Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query string, they are able to change the environment used by the framework when handling the request. The vulnerability fixed in…

  • CVE-2024-3684HigApr 19, 2024
    risk 0.52cvss 8.0epss 0.01

    A server side request forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin access to the appliance when configuring the Artifacts & Logs and Migrations Storage. Exploitation of this…