{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/appwrite/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:appwrite:appwrite:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-89036"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Appwrite (\u003c 2.0.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","rce","argument-injection","appwrite"],"_cs_type":"advisory","_cs_vendors":["Appwrite"],"content_html":"\u003cp\u003eAppwrite versions prior to 2.0.0 contain a critical argument injection vulnerability (CVE-2026-89036) that permits authenticated users with functions.write or sites.write permissions to achieve remote code execution (RCE). The vulnerability stems from the improper sanitization of the providerRootDirectory parameter, which is passed to system commands executing GNU tar. Specifically, the application utilizes the PHP function escapeshellcmd rather than escapeshellarg and fails to wrap the parameter in quotes. This allows an attacker to inject TAB characters, which bypass existing filters and are interpreted as argument separators by the underlying shell. By injecting arbitrary GNU tar arguments, such as --checkpoint-action=exec, an attacker can execute arbitrary code under the context of the builds worker process user. This vulnerability is particularly significant due to the elevated privileges afforded to the builds worker process, potentially allowing for full system compromise within the Appwrite environment.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker obtains or utilizes a valid account with 'functions.write' or 'sites.write' permissions.\u003c/li\u003e\n\u003cli\u003eThe attacker interacts with the application API or UI to configure the 'providerRootDirectory' setting.\u003c/li\u003e\n\u003cli\u003eThe attacker submits a specially crafted 'providerRootDirectory' payload containing one or more TAB characters (0x09) followed by malicious GNU tar flags.\u003c/li\u003e\n\u003cli\u003eThe Appwrite application processes the input using 'escapeshellcmd', which fails to neutralize the injected TAB characters or prevent argument injection.\u003c/li\u003e\n\u003cli\u003eThe application constructs a system command string including the tainted 'providerRootDirectory' parameter.\u003c/li\u003e\n\u003cli\u003eThe shell executes the command, interpreting the TAB-separated segments as distinct arguments to the 'tar' binary.\u003c/li\u003e\n\u003cli\u003eThe 'tar' binary processes the injected '--checkpoint-action=exec' flag.\u003c/li\u003e\n\u003cli\u003eThe 'tar' utility spawns an external process to execute attacker-supplied commands, granting the attacker RCE as the 'builds worker' process user.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for remote code execution on the server running the Appwrite 'builds worker' process. This could lead to full compromise of the affected Appwrite installation, unauthorized access to sensitive application data, exfiltration of environment variables or secrets, and the potential for lateral movement within the hosting infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Appwrite to version 2.0.0 or later immediately to patch the argument injection vulnerability.\u003c/li\u003e\n\u003cli\u003eAudit access logs for the 'functions.write' and 'sites.write' endpoints to identify suspicious attempts to modify configuration parameters containing control characters like TAB.\u003c/li\u003e\n\u003cli\u003eMonitor the 'builds worker' process for the spawning of unexpected child processes or command-line execution patterns associated with 'tar' flags such as '--checkpoint-action'.\u003c/li\u003e\n\u003cli\u003eRestrict permissions for users within the Appwrite console, ensuring the principle of least privilege is applied to those with configuration write access.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-17T17:58:59Z","date_published":"2026-09-17T17:58:59Z","id":"https://feed.craftedsignal.io/briefs/2026-09-appwrite-argument-injection/","summary":"Authenticated users can achieve remote code execution in Appwrite versions before 2.0.0 by exploiting an argument injection vulnerability via the providerRootDirectory parameter in GNU tar commands.","title":"CVE-2026-89036 Argument Injection in Appwrite","url":"https://feed.craftedsignal.io/briefs/2026-09-appwrite-argument-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Appwrite","version":"https://jsonfeed.org/version/1.1"}