Skip to content

Commit fba9b94

Browse files
jasnowRubySec CI
authored andcommitted
Updated advisory posts against rubysec/ruby-advisory-db@9765962
1 parent 7267f80 commit fba9b94

1 file changed

Lines changed: 43 additions & 0 deletions

File tree

Lines changed: 43 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,43 @@
1+
---
2+
layout: advisory
3+
title: 'CVE-2026-12545 (hammer_cli): hammer_cli - Insecure interpolation of the $EDITOR
4+
environment variable'
5+
comments: false
6+
categories:
7+
- hammer_cli
8+
advisory:
9+
gem: hammer_cli
10+
cve: 2026-12545
11+
ghsa: q4vv-h3wg-pwgx
12+
url: https://nvd.nist.gov/vuln/detail/CVE-2026-12545
13+
title: hammer_cli - Insecure interpolation of the $EDITOR environment variable
14+
date: 2026-10-01
15+
description: |-
16+
A flaw was found in rubygem-hammer_cli. A command injection vulnerability
17+
exists in Hammer CLI and the Railties (Ruby on Rails) component
18+
distributed with Satellite due to the insecure interpolation of the
19+
$EDITOR environment variable into the Ruby system() method.
20+
By passing a single interpolated string to system(), the application
21+
invokes a system shell (/bin/sh) that interprets shell
22+
metacharacters (e.g., ;, |, &).
23+
cvss_v3: 6.7
24+
patched_versions:
25+
- "~> 3.19.1"
26+
- ">= 5.0.1"
27+
related:
28+
url:
29+
- https://nvd.nist.gov/vuln/detail/CVE-2026-12545
30+
- https://rubygems.org/gems/hammer_cli/versions/5.0.1
31+
- https://github.com/theforeman/hammer-cli/compare/5.0.0...5.0.1
32+
- https://rubygems.org/gems/hammer_cli/versions/3.19.1
33+
- https://github.com/theforeman/hammer-cli/compare/3.19.0...3.19.1
34+
- https://github.com/theforeman/hammer-cli/pull/407/changes/9d602cd3cecd1e3711037fc4334c3c7d23dbd46b
35+
- https://github.com/theforeman/hammer-cli/commit/a968f58aad9d79bfcd2b107c570f7dcabee033b6
36+
- https://access.redhat.com/errata/RHSA-2026:74503
37+
- https://access.redhat.com/security/cve/CVE-2026-12545
38+
- https://bugzilla.redhat.com/show_bug.cgi?id=2489993
39+
- https://github.com/advisories/GHSA-q4vv-h3wg-pwgx
40+
notes: |
41+
- cvss_v3 from GHSA and nvd-nist.gov URLs.
42+
- date from GHSA URL
43+
---

0 commit comments

Comments
 (0)