Bug 2489993 (CVE-2026-12545) - CVE-2026-12545 rubygem-hammer_cli: command injection via insecure editor invocation
Summary: CVE-2026-12545 rubygem-hammer_cli: command injection via insecure editor invo...
Keywords:
Status: NEW
Alias: CVE-2026-12545
Deadline: 2026-10-01
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-17 17:07 UTC by OSIDB Bzimport
Modified: 2026-10-01 12:59 UTC (History)
14 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-06-17 17:07:40 UTC
Description

A command injection vulnerability exists in Hammer CLI and the Railties (Ruby on Rails) component distributed with Satellite due to the insecure interpolation of the $EDITOR environment variable into the Ruby system() method. By passing a single interpolated string to system(), the application invokes a system shell (/bin/sh) that interprets shell metacharacters (e.g., ;, |, &).

The following files are affected:

lib/hammer_cli/utils.rb - open_in_editor method executes:

--------------------------------------------------------------------------------

system("#{ENV['EDITOR'] || 'vi'} #{f.path}")

--------------------------------------------------------------------------------

railties-7.0.10 , specifically railties-7.0.10/lib/rails/commands/encrypted/encrypted_command.rb and railties-7.0.10/lib/rails/commands/secrets/secrets_command.rb, the framework handles interactive editing via:

--------------------------------------------------------------------------------

system("#{ENV["EDITOR"]} #{tmp_path}")

--------------------------------------------------------------------------------

Impact

This flaw allows a local attacker to execute arbitrary commands within the tool's effective security context. If the utility is run with elevated permissions (e.g., via sudo) while preserving the environment, this leads to root-level privilege escalation.

Recommendations

Use Argument Arrays: Replace system calls that use shell string interpolation with array-based arguments to prevent shell interpretation

Consider updating/upgrading Railties: the version in use (7.0.10) is End-of-Life (EOL). This means the core framework underlying the application will not receive official security patches for this flaw, necessitating manual remediation by the Satellite/Foreman engineering teams or a version upgrade (fixed in the latest version).


Note You need to log in before you can comment on or make changes to this bug.