cwe-88
Safeguard articles tagged "cwe-88" — guides, analysis, and best practices for software supply chain and application security.
7 articles
CVE-2022-36804: Atlassian Bitbucket Server and Data Center Command Injection Vulnerability
CVE-2022-36804 affects Atlassian Bitbucket Server and Data Center and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-09-30.
CVE-2024-41710: Mitel SIP Phones Argument Injection Vulnerability
CVE-2024-41710 affects Mitel SIP Phones and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-02-12.
CVE-2016-10033: PHPMailer Command Injection Vulnerability
CVE-2016-10033 affects PHP PHPMailer and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-07-07.
CVE-2026-24061: GNU InetUtils Argument Injection Vulnerability
CVE-2026-24061 affects GNU InetUtils and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-01-26.
CVE-2026-86060: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
CVE-2026-86060 affects MikroTik RouterOS and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-09-10.
Argument injection vulnerabilities explained
How argument injection (CWE-88) vulnerabilities work, real CVEs like PHPMailer and Git ssh URLs, and how teams detect and prevent CWE-88 flaws.
Argument injection in Git and Mercurial CLI wrappers
A branch name like --upload-pack=/bin/sh isn't a string to Git — it's a flag. CVE-2017-1000117 and CVE-2017-1000116 show why that distinction matters.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.