Sceawere
Vulnerability Detail
CVE-2026-108963UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
databasement Argument Injection RCE
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 2h ago
- Vendor
- David-Crty
- Product
- databasement
- Attack Type
- CWE-88 Improper Neutralization of Argument Delimiters in a Command (Argument Injection)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
databasement before 1.8.2 allows remote code execution because it runs certain commands (e.g., mariadb-dump) with a database name that can be specified by any authenticated user. For example, --result-file=/app/public/index.php can write to index.php. In other words, quoting prevents OS command injection in mariadb-dump, but the argument injection alone is sufficient for code execution indirectly. NOTE: the project's composer.json file does not indicate an independently published databasement Composer package.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-10-11T20:16:32.853Z",
"pubdate": "2026-10-11T20:16:32.853Z",
"executiveSummary": "The databasement package, in versions prior to 1.8.2, contains a critical security vulnerability categorized as an argument injection leading to Remote Code Execution (RCE).\nThe vulnerability originates from the insecure handling of user-supplied input when invoking database administration command-line utilities, specifically mariadb-dump.\nBy manipulating the database name parameter, an authenticated attacker can inject arbitrary command-line flags into the underlying system process execution.\nThis capability allows an attacker to overwrite arbitrary files within the application directory, such as index.php, facilitating the injection and subsequent execution of malicious server-side code.\nThe risk is severe as it provides a pathway for full system compromise, unauthorized data access, and persistent backdoors.\nSuccessful exploitation requires the attacker to be authenticated, though the interface does not require administrative privileges, significantly expanding the potential threat surface for multi-user environments.\nSystem administrators and developers are strongly advised to update to version 1.8.2 or later to mitigate this risk.",
"technicalDetails": "The root cause of this vulnerability is the improper sanitization and validation of input passed to the shell execution environment within the databasement library. When the application triggers a backup or export process, it invokes the mariadb-dump utility. The implementation fails to properly isolate user-controlled data, specifically the database name argument, before passing it as a parameter to the command-line interface.\nWhile the developer attempted to implement defenses against traditional OS command injection by applying quoting to the arguments, this approach failed to prevent argument injection. In the context of mariadb-dump, an attacker can supply flags as part of the database name string. Because these flags are parsed by the mariadb-dump binary, the attacker can alter the utility's default behavior, such as modifying output redirection or configuration parameters.\nA typical attack flow involves an authenticated user submitting a crafted database name string, such as '--result-file=/app/public/index.php'. When the application processes this request, it executes a command resembling: mariadb-dump [options] --result-file=/app/public/index.php [other-options]. The inclusion of the --result-file flag forces the binary to output its dump content into the specified file path, effectively overwriting the target file.\nIf an attacker points this redirection to a sensitive web-accessible file (e.g., index.php), they can replace the existing legitimate content with a valid SQL dump containing malicious PHP code. Once the file is overwritten, the attacker can trigger the execution of the injected code by requesting the file through a standard HTTP request to the web server, resulting in full remote code execution under the privileges of the web application user.\nThe vulnerability affects all versions of databasement before 1.8.2. Exploitation is contingent upon the attacker maintaining an authenticated session. The impact is absolute, as arbitrary file write primitives permit the modification of any file within the web server's writeable scope, allowing for persistent malware installation, configuration tampering, or data exfiltration. Given the ubiquity of database operations in web applications, this vulnerability poses a significant risk to the integrity and confidentiality of the entire hosting environment."
}