Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 01 Oct 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in rubygem-hammer_cli. A command injection vulnerability exists in Hammer CLI and the Railties (Ruby on Rails) component distributed with Satellite due to the insecure interpolation of the $EDITOR environment variable into the Ruby system() method. By passing a single interpolated string to system(), the application invokes a system shell (/bin/sh) that interprets shell metacharacters (e.g., ;, |, &). | |
| Title | Rubygem-hammer_cli: command injection via insecure editor invocation | |
| First Time appeared |
Redhat
Redhat satellite Redhat satellite Capsule Redhat satellite Utils |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:/a:redhat:satellite:6 cpe:/a:redhat:satellite:6.19::el9 cpe:/a:redhat:satellite_capsule:6.19::el9 cpe:/a:redhat:satellite_utils:6.19::el9 |
|
| Vendors & Products |
Redhat
Redhat satellite Redhat satellite Capsule Redhat satellite Utils |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-01T17:33:12.351Z
Reserved: 2026-06-17T17:42:24.665Z
Link: CVE-2026-12545
Updated: 2026-10-01T17:33:09.374Z
Status : Received
Published: 2026-10-01T18:17:15.700
Modified: 2026-10-01T18:17:15.700
Link: CVE-2026-12545
No data.
OpenCVE Enrichment
Updated: 2026-10-01T19:00:16Z
-
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')