CWE-88: Argument Injection
The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.
254 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-24061 — telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
- CVE-2024-24576 — Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
- CVE-2024-47553 — A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not
- CVE-2024-47516 — Pagure: argument injection in pagurerepo.log()
- CVE-2026-27947 — Group-Office Vulnerable to Remote Code Execution (RCE)
- CVE-2026-25134 — Group-Office Argument Injection in MaintenanceController::actionZipLanguage
- CVE-2025-49008 — Atheos Improper Input Validation Vulnerability Enables RCE in Common.php
- CVE-2025-21613 — go-git has an Argument Injection via the URL field
- CVE-2025-32931 — DevDojo Voyager 1.4.0 through 1.8.0, when Laravel 8 or later is used, allows authenticated administrators to execute arb
- CVE-2026-26194 — Gogs: Release tag option injection in release deletion
- CVE-2026-0774 — WatchYourLAN Configuration Page Argument Injection Remote Code Execution Vulnerability
- CVE-2025-49520 — Event-driven-ansible: authenticated argument injection in git url in eda project creation
- CVE-2025-12556 — IDIS ICM Viewer Argument Injection
- CVE-2025-1712 — Arbitrary file write with vcrtrace
- CVE-2024-52301 — Laravel allows environment manipulation via query string
- CVE-2025-47421 — Privilege escalation via SCP login
- CVE-2024-22182 — Commend WS203VICM Argument Injection
- CVE-2025-6232 — An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local at
- CVE-2025-6231 — An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local at
- CVE-2025-43730 — Dell ThinOS 10, versions prior to 2508_10.0127, contains an Improper Neutralization of Argument Delimiters in a Command
Recently published
- CVE-2026-8044 — CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability exists that cou
- CVE-2026-87818 — GitPython 3.1.59 Local File Content Oracle via --no-index
- CVE-2026-87794 — bestzip 2.2.6 and 3.0.2 Argument Injection via the Native Zip Destination
- CVE-2026-78635 — Improper Input Validation in the Okta Privileged Access SSH Client URL Handler Argument
- CVE-2026-71377 — Command Argument Injection Vulnerability in Cosminexus Component Container
- CVE-2026-84256 — An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authe
- CVE-2026-86060 — SSH session privilege manipulation via a crafted username in Mikrotik RouterOS
- CVE-2026-85626 — git-mcp-server 2.15.1 Argument Injection via Git Ref Parameters
- CVE-2026-74237 — GFI Exinda AI / ClearView < 7.6.5 Argument Injection via Tools Iperf Client
- CVE-2026-79685 — Dell PowerStore contains an Argument Injection vulnerability. An authenticated user with limited privileges could potent
- CVE-2026-55673 — PowSyBl: Command Injection in LocalCommandExecutor-s
- CVE-2026-54085 — Wazuh: Missing input validation in multiple active response scripts allows argument injection
- CVE-2026-81529 — Connection-option injection via unescaped settings in the canonical MongoDB URL builder
- CVE-2026-80427 — bestzip before 2.2.6 and 3.0.x before 3.0.2 Argument Injection via Missing Option Delimiter
- CVE-2026-79675 — NLTK before 3.10.3 JVM Argument Injection via Per-Call Options
- CVE-2026-78637 — Fdawgs node-poppler Argument Injection index.js pdfUnite argument injection
- CVE-2026-78678 — GitPython before 3.1.59 Arbitrary File Read via Repo.blame()
- CVE-2026-78676 — GitPython before 3.1.59 Remote Code Execution via Config Injection
- CVE-2026-68766 — hashcat through 7.1.2 Arbitrary File Write via Restore File Option Injection
- CVE-2026-62867 — Incus has an argument injection in storage volume block.create_options that leads to arbitrary command execution