Appium is a test-automation framework for mobile and web applications, with a narrow product portfolio centered on its desktop environment and ChromeDriver integration. The durable signal in its disclosures centers on path-traversal, OS command injection, and missing encryption of sensitive data—weakness classes typical of automation tools that bridge local development environments with external drivers and handle user-supplied test configurations. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Appium over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-2479CRITICAL OS Command Injection in GitHub repository appium/appium-desktop prior to v1.22.3-4. | May 2, 2023 | 9.8 | 55 | NO | YES |
CVE-2026-58191MEDIUM Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 10.7.0, Appium's base-driver unconditionally mounts the | Jul 8, 2026 | 6.1 | 26 | NO | NO |
CVE-2016-10557HIGH appium-chromedriver is a Node.js wrapper around Chromedriver. Versions below 2.9.4 download binary resources over HTTP, which leaves the module vulnerable to MITM attacks. It may b | May 31, 2018 | 8.1 | 23 | NO | NO |
CVE-2026-30973MEDIUM Appium is an automation framework that provides WebDriver-based automation possibilities for a wide range platforms. Prior to 7.0.6, @appium/support contains a ZIP extraction imple | Mar 10, 2026 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Appium.
Media articles that mention a CVE ID that affects a product developed by Appium — matched by CVE ID, not by vendor name.