Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint v
Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-
Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache
Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the MCP server creation endpoint validates the command
Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated
Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied fil
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th
Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handlin
Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `b
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing
TOTOLINK X5000R v9.1.0cu_2415_B20250515 contains an argument injection vulnerability in the setDiagnosisCfg handler of t
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. A vulnerability in versions prior to 2.01 allows unau
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to 3.0.14, the creat
In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter
Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix
ArchiveBox is an open source self-hosted web archiving system. In versions 0.8.6rc0 and prior, the /add/ endpoint (AddVi
The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a command-line argument injection vulnerability in its Kub
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command
MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubect
Specifically crafted inputs may lead to git argument injection in Apache Allura. This issue affects Apache Allura: befo
PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document
GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting do
NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, a
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior,
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing
bleon-ethical/api-gateway-deploy provides API gateway deployment. Version 1.0.0 is vulnerable to an attack chain involvi
Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file
OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the XMLRPC method opnsense.restore_config_se
OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsanitized user input is passed to the DHCP
Lumiverse is a full-featured AI chat application. Prior to 0.9.7, when the primary toSmbPath(fullPath) call throws, the
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling
WatchYourLAN Configuration Page Argument Injection Remote Code Execution Vulnerability. This vulnerability allows networ
Group-Office is an enterprise customer relationship management and groupware tool. Prior to 6.8.150, 25.0.82, and 26.0.5
Group-Office is an enterprise customer relationship management and groupware tool. Versions prior to 26.0.9, 25.0.87, an
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Archit
IINA before 1.4.3 contains a user-assisted command execution vulnerability that allows remote attackers to execute arbit
n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with pe
Jellyfin is an open source self hosted media server. Prior to 10.11.10, a potential FFmpeg argument injection vulnerabil
A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. The extensio
Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM Softw
Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, src/core/git/gitCommand.ts execGitSha
An argument injection vulnerability in PrefectHQ Prefect through 3.8.2 allows authenticated users to achieve remote code
GitPython before 3.1.58 contains a command execution vulnerability in the check_unsafe_options guard that can be bypasse
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InLong. Agent
A vulnerability in the `GitHubRepository` block of the `prefect-github` integration in Prefect version 3.6.18 allows an
PraisonAI is a multi-agent teams system. Prior to 4.5.128, deploy.py constructs a single comma-delimited string for the
bestzip builds the argument list for the system zip utility without separating options from operands. The destination ar
mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Versions 3.4.0 and prior con
Frequently Asked Questions
What is CWE-88?
CWE-88 (CWE-88) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-88?
There are 146 CVE records associated with CWE-88 in our database. Of these, 33 are critical severity, 66 are high severity, and 28 are medium severity.
How can I protect against CWE-88 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-88 using AI-powered security agents.
Detect CWE-88 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-88 vulnerabilities across your infrastructure.
Get Started