|
| 1 | +--- |
| 2 | +layout: advisory |
| 3 | +title: 'CVE-2026-12545 (hammer_cli): hammer_cli - Insecure interpolation of the $EDITOR |
| 4 | + environment variable' |
| 5 | +comments: false |
| 6 | +categories: |
| 7 | +- hammer_cli |
| 8 | +advisory: |
| 9 | + gem: hammer_cli |
| 10 | + cve: 2026-12545 |
| 11 | + ghsa: q4vv-h3wg-pwgx |
| 12 | + url: https://nvd.nist.gov/vuln/detail/CVE-2026-12545 |
| 13 | + title: hammer_cli - Insecure interpolation of the $EDITOR environment variable |
| 14 | + date: 2026-10-01 |
| 15 | + description: |- |
| 16 | + A flaw was found in rubygem-hammer_cli. A command injection vulnerability |
| 17 | + exists in Hammer CLI and the Railties (Ruby on Rails) component |
| 18 | + distributed with Satellite due to the insecure interpolation of the |
| 19 | + $EDITOR environment variable into the Ruby system() method. |
| 20 | + By passing a single interpolated string to system(), the application |
| 21 | + invokes a system shell (/bin/sh) that interprets shell |
| 22 | + metacharacters (e.g., ;, |, &). |
| 23 | + cvss_v3: 6.7 |
| 24 | + patched_versions: |
| 25 | + - "~> 3.19.1" |
| 26 | + - ">= 5.0.1" |
| 27 | + related: |
| 28 | + url: |
| 29 | + - https://nvd.nist.gov/vuln/detail/CVE-2026-12545 |
| 30 | + - https://rubygems.org/gems/hammer_cli/versions/5.0.1 |
| 31 | + - https://github.com/theforeman/hammer-cli/compare/5.0.0...5.0.1 |
| 32 | + - https://rubygems.org/gems/hammer_cli/versions/3.19.1 |
| 33 | + - https://github.com/theforeman/hammer-cli/compare/3.19.0...3.19.1 |
| 34 | + - https://github.com/theforeman/hammer-cli/pull/407/changes/9d602cd3cecd1e3711037fc4334c3c7d23dbd46b |
| 35 | + - https://github.com/theforeman/hammer-cli/commit/a968f58aad9d79bfcd2b107c570f7dcabee033b6 |
| 36 | + - https://access.redhat.com/errata/RHSA-2026:74503 |
| 37 | + - https://access.redhat.com/security/cve/CVE-2026-12545 |
| 38 | + - https://bugzilla.redhat.com/show_bug.cgi?id=2489993 |
| 39 | + - https://github.com/advisories/GHSA-q4vv-h3wg-pwgx |
| 40 | + notes: | |
| 41 | + - cvss_v3 from GHSA and nvd-nist.gov URLs. |
| 42 | + - date from GHSA URL |
| 43 | +--- |
0 commit comments