Description
Appwrite before 2.0.0 contains an argument injection vulnerability that allows authenticated users with functions.write or sites.write permissions to execute arbitrary commands by injecting TAB characters into the providerRootDirectory parameter used to construct GNU tar commands. The application uses escapeshellcmd instead of escapeshellarg and fails to quote the parameter, allowing TAB characters to survive sanitization and be interpreted as argument separators, enabling injection of arbitrary GNU tar arguments such as --checkpoint-action=exec to achieve remote code execution as the builds worker process user.
Published: 2026-09-17
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution via argument injection
Action: Immediate Patch
AI Analysis

Impact

Appwrite versions before 2.0.0 contain an argument injection flaw in the providerRootDirectory parameter. Because the application uses escapeshellcmd rather than escapeshellarg and does not quote the parameter, TAB characters can survive sanitization. These TABs are interpreted by GNU tar as argument separators, allowing the injection of arbitrary tar options such as --checkpoint-action=exec. An attacker who is authenticated and holds functions.write or sites.write rights can specify a crafted value, causing the build worker process to execute arbitrary commands. The vulnerability directly leads to remote code execution with the privileges of the worker process.

Affected Systems

The flaw exists in all Appwrite releases prior to 2.0.0. Users running the appwrite:appwrite product under any earlier version are affected, regardless of deployment environment. The issue is tied to the providerRootDirectory functionality exposed by the API handling functions and sites, so any instance that exposes those endpoints to authenticated users is at risk.

Risk and Exploitability

The CVSS score of 8.7 classifies this as a high‑severity vulnerability. Although the EPSS score is less than 1%, indicating a low probability of exploitation, the flaw is not present in CISA’s KEV catalog, so no known widespread attacks have been reported at the time of analysis. The attack requires validated credentials with functions.write or sites.write permissions, but once authenticated it can bypass further checks and execute arbitrary commands as the builds worker. The ease of exploitation and the high impact suggest that this should be treated as a critical maintenance item for any system still running a vulnerable Appwrite version.

Generated by OpenCVE AI on September 20, 2026 at 04:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Appwrite 2.0.0 release or later to remove the vulnerable code path.
  • Restrict or remove functions.write and sites.write permissions for users until the patch is applied, ensuring no authenticated user can trigger the tar command.
  • If an immediate upgrade is not possible, consider disabling or limiting the usage of the providerRootDirectory parameter in configuration or code, or patch the application to use escapeshellarg and properly quote the input before it is passed to GNU tar.

Generated by OpenCVE AI on September 20, 2026 at 04:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:appwrite:appwrite:*:*:*:*:*:*:*:*

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Appwrite
Appwrite appwrite
Vendors & Products Appwrite
Appwrite appwrite

Thu, 17 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description Appwrite before 2.0.0 contains an argument injection vulnerability that allows authenticated users with functions.write or sites.write permissions to execute arbitrary commands by injecting TAB characters into the providerRootDirectory parameter used to construct GNU tar commands. The application uses escapeshellcmd instead of escapeshellarg and fails to quote the parameter, allowing TAB characters to survive sanitization and be interpreted as argument separators, enabling injection of arbitrary GNU tar arguments such as --checkpoint-action=exec to achieve remote code execution as the builds worker process user.
Title Appwrite < 2.0.0 Argument Injection via providerRootDirectory Parameter
Weaknesses CWE-88
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Appwrite Appwrite
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T15:21:54.929Z

Reserved: 2026-09-10T16:23:54.472Z

Link: CVE-2026-89036

cve-icon Vulnrichment

Updated: 2026-09-17T17:03:56.941Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T16:18:28.540

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-89036

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:30:18Z

Weaknesses
  • CWE-88

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')