Command Injection Vulnerability in Hammer CLI and Railties by Red Hat
CVE-2026-12545

6.7MEDIUM

What is CVE-2026-12545?

A command injection vulnerability was identified in Hammer CLI and the Railties component of Ruby on Rails distributed with Satellite. This flaw arises from the insecure interpolation of the $EDITOR environment variable into the Ruby system() method. The exploitation of this vulnerability occurs when an attacker is able to pass a malformed string to the system() method, which results in invoking a system shell that unwittingly interprets shell metacharacters. If exploited, this vulnerability could lead to undesired execution of commands within the system, enhancing the risk of a security breach.

Affected Version(s)

Red Hat Satellite 6.19 for RHEL 9 0:3.18.0-2.el9sat

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Laura Pardo (Red Hat) and Toni Gornals (Red Hat).
.