CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.
393 vulnerabilities with CWE-88
CVE-2026-18157
HIGH
Yggdrasil-worker-package-manager: yggdrasil-worker-package-manager: remote code execution via apt argument injection
CVSS 7.8
CVE-2026-43698
HIGH
Apple macOS - Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
CVSS 7.8
CVE-2026-16796
HIGH
Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()
CVSS 7.3
CVE-2026-44210
MEDIUM
Kata Containers have VM Escape via virtiofsd Argument Injection through Default-Enabled Pod Annotations
CVE-2026-44189
HIGH
Ansible-lightspeed: visual studio code ansible lightspeed extension: arbitrary code execution via malicious playbook filename
CVSS 7.8
CVE-2026-16493
HIGH
Red Hat ansible-core - ansible-galaxy Git Collection Argument Injection
CVSS 7.8
CVE-2026-15793
HIGH
Git source checkout from a bundle file could lead to command injection
CVSS 7.5
CVE-2026-64624
HIGH
FreeRDP RDP File Parser Remote Code Execution via CLI Options
CVSS 7.8
CVE-2026-44968
MEDIUM
dbt-mcp: Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type Parameters
CVSS 6.3
CVE-2026-52891
CRITICAL
Wekan: Shell Injection via Avatar Upload
CVSS 9.9
CVE-2026-49987
HIGH
Repomix: Command Injection (RCE) via `--remote-branch` Argument Injection
CVE-2026-50147
HIGH
Metabase: Arbitrary File Read via MySQL Connection Property Injection
CVSS 7.6
CVE-2026-45068
HIGH
Symfony: Argument Injection in SendmailTransport via Dash-Prefixed Recipient Address
CVSS 7.5
CVE-2026-61459
CRITICAL
MCP Server Kubernetes < 3.9.0 Argument Injection via kubectl Structured Tools
CVSS 9.8
CVE-2026-47829
HIGH
BOSH CLI < 7.10.4 - Local Command Execution via SSH Argument Injection
CVSS 7.8
CVE-2026-57572
CRITICAL
Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args
CVSS 10.0
CVE-2026-40047
CRITICAL
Apache Camel: Camel-Docling: Insufficient validation of custom CLI arguments enables argument injection and path traversal in DoclingProducer
CVSS 9.1
CVE-2026-14459
HIGH
Argument Injection in TUBITAK BILGEM's pardus-software
CVSS 8.8
CVE-2026-12856
HIGH
Red Hat OpenShift Dev Spaces vscode-java Javadoc Hover - Command Injection
CVSS 8.8
CVE-2026-54088
CRITICAL
File Browser < 2.63.6 - Pre-Authentication Remote Code Execution
CVE-2026-50014
MEDIUM
pnpm: Git Fetch Argument Injection via Lockfile resolution.commit
CVSS 6.4
CVE-2026-40079
CRITICAL
Cacti: Command Injection via escape_command() no-op in RRDtool execution
CVSS 9.8
CVE-2026-48793
HIGH
Jellyfin: Potential FFmpeg argument injection via unescaped subtitle file path
CVSS 8.8
CVE-2026-54686
MEDIUM
Warp: DCS lifecycle hook spoofing can alter terminal session metadata
CVSS 4.3
CVE-2026-11968
MEDIUM
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') in TortoiseGit
CVSS 5.5
Details
Vulnerabilities
393