CWE-88Base1 in KEV

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

Draft in the CWE catalog · 252 CVEs mapped

252
CVEs mapped
1
In KEV
7.8
Median CVSS
What it is

The product constructs a string for a command to be executed by a separate component

in another control sphere, but it does not properly delimit the

intended arguments, options, or switches within that command string.

Recent examples
7.7cvss
CVE-2026-84256

An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to execute arbitrary…

An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to execute arbitrary commands via a crafted certificate subject

HIGHno explanation yet
epss
none
CVE-2026-86060

CVE-2026-86060 - UNKNOWN Severity Vulnerability

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

no explanation yet
0%
epss
7.5cvss
CVE-2026-85626

CVE-2026-85626 - HIGH Severity Vulnerability

git-mcp-server 2.15.1 contains an argument injection vulnerability in the ref and object parameters of git_log, git_diff, and git_show tools that lack leading-dash validation. Attackers can inject git command-line options like --output= to write files outside the repository to arbitrary paths accessible by the process.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-88
Abstraction
Base
Structure
Simple
Status
Draft
References (4)