Impact
Appwrite versions before 2.0.0 contain an argument injection flaw in the providerRootDirectory parameter. Because the application uses escapeshellcmd rather than escapeshellarg and does not quote the parameter, TAB characters can survive sanitization. These TABs are interpreted by GNU tar as argument separators, allowing the injection of arbitrary tar options such as --checkpoint-action=exec. An attacker who is authenticated and holds functions.write or sites.write rights can specify a crafted value, causing the build worker process to execute arbitrary commands. The vulnerability directly leads to remote code execution with the privileges of the worker process.
Affected Systems
The flaw exists in all Appwrite releases prior to 2.0.0. Users running the appwrite:appwrite product under any earlier version are affected, regardless of deployment environment. The issue is tied to the providerRootDirectory functionality exposed by the API handling functions and sites, so any instance that exposes those endpoints to authenticated users is at risk.
Risk and Exploitability
The CVSS score of 8.7 classifies this as a high‑severity vulnerability. Although the EPSS score is less than 1%, indicating a low probability of exploitation, the flaw is not present in CISA’s KEV catalog, so no known widespread attacks have been reported at the time of analysis. The attack requires validated credentials with functions.write or sites.write permissions, but once authenticated it can bypass further checks and execute arbitrary commands as the builds worker. The ease of exploitation and the high impact suggest that this should be treated as a critical maintenance item for any system still running a vulnerable Appwrite version.
OpenCVE Enrichment