A flaw was found in rubygem-hammer_cli. (CVE-2026-12545)
A command injection vulnerability exists in rubygem-hammer_cli due to insecure interpolation of the $EDITOR environment variable into Ruby's system() method. This flaw allows shell metacharacters to be interpreted, potentially leading to arbitrary command execution. The vulnerability affects Red Hat Satellite 6.19 on RHEL 9 and has been assigned CVE-2026-12545 with a CVSS score of 6.7 (medium severity). Red Hat has released an official security advisory and patch to address this issue.
AI Analysis
Technical Summary
CVE-2026-12545 is a command injection vulnerability in rubygem-hammer_cli and the Railties component distributed with Red Hat Satellite. The vulnerability arises from insecure interpolation of the $EDITOR environment variable into Ruby's system() method, which invokes a system shell that interprets shell metacharacters. This can allow an attacker with limited privileges to execute arbitrary commands on the affected system. The issue is addressed in a security update released by Red Hat for Satellite 6.19 on RHEL 9.
Potential Impact
Successful exploitation of this vulnerability can lead to high impact including confidentiality, integrity, and availability compromise due to arbitrary command execution. The CVSS v3.1 score is 6.7, reflecting medium severity with local attack vector, high privileges required, and user interaction needed. There are no known exploits in the wild at this time.
Mitigation Recommendations
Red Hat has released an official security advisory (RHSA-2026:74503) providing patches for Red Hat Satellite 6.19 on RHEL 9 to fix this vulnerability. Users should apply the update as instructed in the advisory. No additional mitigation steps are required beyond applying the official patch.
A flaw was found in rubygem-hammer_cli. (CVE-2026-12545)
Description
A command injection vulnerability exists in rubygem-hammer_cli due to insecure interpolation of the $EDITOR environment variable into Ruby's system() method. This flaw allows shell metacharacters to be interpreted, potentially leading to arbitrary command execution. The vulnerability affects Red Hat Satellite 6.19 on RHEL 9 and has been assigned CVE-2026-12545 with a CVSS score of 6.7 (medium severity). Red Hat has released an official security advisory and patch to address this issue.
CVSS v3.1
Score 6.7medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-12545 is a command injection vulnerability in rubygem-hammer_cli and the Railties component distributed with Red Hat Satellite. The vulnerability arises from insecure interpolation of the $EDITOR environment variable into Ruby's system() method, which invokes a system shell that interprets shell metacharacters. This can allow an attacker with limited privileges to execute arbitrary commands on the affected system. The issue is addressed in a security update released by Red Hat for Satellite 6.19 on RHEL 9.
Potential Impact
Successful exploitation of this vulnerability can lead to high impact including confidentiality, integrity, and availability compromise due to arbitrary command execution. The CVSS v3.1 score is 6.7, reflecting medium severity with local attack vector, high privileges required, and user interaction needed. There are no known exploits in the wild at this time.
Mitigation Recommendations
Red Hat has released an official security advisory (RHSA-2026:74503) providing patches for Red Hat Satellite 6.19 on RHEL 9 to fix this vulnerability. Users should apply the update as instructed in the advisory. No additional mitigation steps are required beyond applying the official patch.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-q4vv-h3wg-pwgx
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-12545"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
- State
- PUBLISHED
Patch Information
Threat ID: 6abeb3e1a43b0b3b89ecc9e4
Added to database: 10/01/2026, 19:26:25 UTC
Last enriched: 10/01/2026, 19:27:21 UTC
Last updated: 10/02/2026, 00:45:56 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.