Bug 2506495 (CVE-2026-16733)
| Summary: | CVE-2026-16733 find-cypress-specs: bahmutov find-cypress-specs: OS Command Injection via Branch Argument Manipulation | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | ataylor, dbruscin, ehugonne, kvanderr |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in bahmutov find-cypress-specs. A local attacker can exploit a vulnerability in the Branch Handler component by manipulating the '--branch' argument. This manipulation leads to an operating system (OS) command injection, allowing the attacker to execute arbitrary commands on the system. This could result in unauthorized access, modification, or disruption of data and system resources.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-07-23 15:01:57 UTC
|