Sceawere

Vulnerability Detail

CVE-2026-108963UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

databasement Argument Injection RCE

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
2h ago
Vendor
David-Crty
Product
databasement
Attack Type
CWE-88 Improper Neutralization of Argument Delimiters in a Command (Argument Injection)
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

databasement before 1.8.2 allows remote code execution because it runs certain commands (e.g., mariadb-dump) with a database name that can be specified by any authenticated user. For example, --result-file=/app/public/index.php can write to index.php. In other words, quoting prevents OS command injection in mariadb-dump, but the argument injection alone is sufficient for code execution indirectly. NOTE: the project's composer.json file does not indicate an independently published databasement Composer package.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-10-11T20:16:32.853Z",
  "pubdate": "2026-10-11T20:16:32.853Z",
  "executiveSummary": "The databasement package, in versions prior to 1.8.2, contains a critical security vulnerability categorized as an argument injection leading to Remote Code Execution (RCE).\nThe vulnerability originates from the insecure handling of user-supplied input when invoking database administration command-line utilities, specifically mariadb-dump.\nBy manipulating the database name parameter, an authenticated attacker can inject arbitrary command-line flags into the underlying system process execution.\nThis capability allows an attacker to overwrite arbitrary files within the application directory, such as index.php, facilitating the injection and subsequent execution of malicious server-side code.\nThe risk is severe as it provides a pathway for full system compromise, unauthorized data access, and persistent backdoors.\nSuccessful exploitation requires the attacker to be authenticated, though the interface does not require administrative privileges, significantly expanding the potential threat surface for multi-user environments.\nSystem administrators and developers are strongly advised to update to version 1.8.2 or later to mitigate this risk.",
  "technicalDetails": "The root cause of this vulnerability is the improper sanitization and validation of input passed to the shell execution environment within the databasement library. When the application triggers a backup or export process, it invokes the mariadb-dump utility. The implementation fails to properly isolate user-controlled data, specifically the database name argument, before passing it as a parameter to the command-line interface.\nWhile the developer attempted to implement defenses against traditional OS command injection by applying quoting to the arguments, this approach failed to prevent argument injection. In the context of mariadb-dump, an attacker can supply flags as part of the database name string. Because these flags are parsed by the mariadb-dump binary, the attacker can alter the utility's default behavior, such as modifying output redirection or configuration parameters.\nA typical attack flow involves an authenticated user submitting a crafted database name string, such as '--result-file=/app/public/index.php'. When the application processes this request, it executes a command resembling: mariadb-dump [options] --result-file=/app/public/index.php [other-options]. The inclusion of the --result-file flag forces the binary to output its dump content into the specified file path, effectively overwriting the target file.\nIf an attacker points this redirection to a sensitive web-accessible file (e.g., index.php), they can replace the existing legitimate content with a valid SQL dump containing malicious PHP code. Once the file is overwritten, the attacker can trigger the execution of the injected code by requesting the file through a standard HTTP request to the web server, resulting in full remote code execution under the privileges of the web application user.\nThe vulnerability affects all versions of databasement before 1.8.2. Exploitation is contingent upon the attacker maintaining an authenticated session. The impact is absolute, as arbitrary file write primitives permit the modification of any file within the web server's writeable scope, allowing for persistent malware installation, configuration tampering, or data exfiltration. Given the ubiquity of database operations in web applications, this vulnerability poses a significant risk to the integrity and confidentiality of the entire hosting environment."
}