CPE
Authenticated users can achieve remote code execution in Appwrite versions before 2.0.0 by exploiting an argument injection vulnerability via the providerRootDirectory parameter in GNU tar commands.