PatchSiren

appwrite CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH appwrite CVE published 2026-09-17

CVE-2026-89036

CVE-2026-89036 is an argument injection vulnerability in Appwrite before version 2.0.0. Authenticated users with functions.write or sites.write permissions can inject TAB characters into the providerRootDirectory parameter, allowing for arbitrary command execution as the builds worker process user. This vulnerability enables attackers to execute arbitrary commands, potentially leading to remote code execu [truncated]

MEDIUM appwrite CVE published 2026-08-20

CVE-2026-72861

The github-issue-bot templates in appwrite/templates verify the GitHub webhook signature with an inverted condition, allowing unauthenticated requests to pass the check. This occurs because verifyWebhook in node/github-issue-bot/src/github.js and node-typescript/github-issue-bot/src/github.ts returns 'typeof signature !== 'string' || (await verify(...))', causing the function to report success without HMA [truncated]