OS Command Injection Vulnerability in Fleet Maintained MacOS Apps via Homebrew
CVE-2026-101045
What is CVE-2026-101045?
The vulnerability in Fleet's app installation scripts for macOS results from improper escaping of Homebrew cask metadata prior to August 19, 2026. An attacker can exploit this flaw to inject shell metacharacters into scripts that execute with root privileges on managed macOS systems. This security oversight allows arbitrary command execution when crafted metadata is submitted to an upstream Homebrew cask without the need for Fleet credentials. Despite the chance of pre-existing review processes, successful exploitation provides significant control over affected systems. A remediation was deployed on August 19, 2026, ensuring that subsequent manifests escape cask metadata appropriately and applies to all affected deployments without user intervention.
