CVE-2026-89036 is an argument injection vulnerability in Appwrite before version 2.0.0. Authenticated users with functions.write or sites.write permissions can inject TAB characters into the providerRootDirectory parameter, allowing for arbitrary command execution as the builds worker process user. This vulnerability enables attackers to execute arbitrary commands, potentially leading to remote code execu [truncated]
The github-issue-bot templates in appwrite/templates verify the GitHub webhook signature with an inverted condition, allowing unauthenticated requests to pass the check. This occurs because verifyWebhook in node/github-issue-bot/src/github.js and node-typescript/github-issue-bot/src/github.ts returns 'typeof signature !== 'string' || (await verify(...))', causing the function to report success without HMA [truncated]