Bug 2489993 (CVE-2026-12545)
| Summary: | CVE-2026-12545 rubygem-hammer_cli: command injection via insecure editor invocation | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | anthomas, ehelms, ggainey, jpasqual, juwatts, mdellweg, mhulan, nmoumoul, osousa, pcreech, rchan, security-response-team, smallamp, tmalecek |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in rubygem-hammer_cli. A command injection vulnerability exists in Hammer CLI and the Railties (Ruby on Rails) component distributed with Satellite due to the insecure interpolation of the $EDITOR environment variable into the Ruby system() method. By passing a single interpolated string to system(), the application invokes a system shell (/bin/sh) that interprets shell metacharacters (e.g., ;, |, &).
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Deadline: | 2026-10-01 | ||
Description A command injection vulnerability exists in Hammer CLI and the Railties (Ruby on Rails) component distributed with Satellite due to the insecure interpolation of the $EDITOR environment variable into the Ruby system() method. By passing a single interpolated string to system(), the application invokes a system shell (/bin/sh) that interprets shell metacharacters (e.g., ;, |, &). The following files are affected: lib/hammer_cli/utils.rb - open_in_editor method executes: -------------------------------------------------------------------------------- system("#{ENV['EDITOR'] || 'vi'} #{f.path}") -------------------------------------------------------------------------------- railties-7.0.10 , specifically railties-7.0.10/lib/rails/commands/encrypted/encrypted_command.rb and railties-7.0.10/lib/rails/commands/secrets/secrets_command.rb, the framework handles interactive editing via: -------------------------------------------------------------------------------- system("#{ENV["EDITOR"]} #{tmp_path}") -------------------------------------------------------------------------------- Impact This flaw allows a local attacker to execute arbitrary commands within the tool's effective security context. If the utility is run with elevated permissions (e.g., via sudo) while preserving the environment, this leads to root-level privilege escalation. Recommendations Use Argument Arrays: Replace system calls that use shell string interpolation with array-based arguments to prevent shell interpretation Consider updating/upgrading Railties: the version in use (7.0.10) is End-of-Life (EOL). This means the core framework underlying the application will not receive official security patches for this flaw, necessitating manual remediation by the Satellite/Foreman engineering teams or a version upgrade (fixed in the latest version).