Safeguard
Tag

cwe-88

Safeguard articles tagged "cwe-88" — guides, analysis, and best practices for software supply chain and application security.

7 articles

Vulnerability Analysis

CVE-2022-36804: Atlassian Bitbucket Server and Data Center Command Injection Vulnerability

CVE-2022-36804 affects Atlassian Bitbucket Server and Data Center and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-09-30.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2024-41710: Mitel SIP Phones Argument Injection Vulnerability

CVE-2024-41710 affects Mitel SIP Phones and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-02-12.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2016-10033: PHPMailer Command Injection Vulnerability

CVE-2016-10033 affects PHP PHPMailer and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-07-07.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2026-24061: GNU InetUtils Argument Injection Vulnerability

CVE-2026-24061 affects GNU InetUtils and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-01-26.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2026-86060: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability

CVE-2026-86060 affects MikroTik RouterOS and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-09-10.

Sep 17, 20263 min read
Vulnerability Analysis

Argument injection vulnerabilities explained

How argument injection (CWE-88) vulnerabilities work, real CVEs like PHPMailer and Git ssh URLs, and how teams detect and prevent CWE-88 flaws.

Jul 28, 20267 min read
Application Security

Argument injection in Git and Mercurial CLI wrappers

A branch name like --upload-pack=/bin/sh isn't a string to Git — it's a flag. CVE-2017-1000117 and CVE-2017-1000116 show why that distinction matters.

Jul 10, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.