Red Hat Security Advisory: RHTAS 1.2.2 - Red Hat Trusted Artifact Signer Release
The RHTAS Operator can be used with OpenShift Container Platform 4.15, 4.16, 4.17, 4.18 and 4.19
AI Analysis
Technical Summary
CVE-2025-64756 is a command injection vulnerability in the glob CLI component used by Red Hat Trusted Artifact Signer (RHTAS) versions >=1.2.0 <1.2.2. The glob CLI uses the -c/--cmd option to execute shell commands on files matching a pattern, but it fails to sanitize filenames containing shell metacharacters. This allows an attacker who can create or influence filenames processed by glob to execute arbitrary OS commands. The vulnerability is due to the shell:true parameter used in subprocess execution, which interprets shell metacharacters in filenames. Exploitation requires the attacker to have permission to create or trick the user into processing maliciously named files. The vulnerability is present in the glob CLI but not in the programmatic use of the glob package by npm. Red Hat has not yet released a patch for RHTAS but has published advisory RHSA-2026:2925 describing the issue and mitigation recommendations.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary operating system commands with the privileges of the user running the glob CLI. This can lead to unauthorized code execution, data modification or disclosure, and potential denial of service by crashing or disrupting the application. Because the commands execute in the context of the application, malicious actions may appear to originate from the application or its owner, complicating detection and attribution.
Mitigation Recommendations
Avoid using the glob CLI with the -c or --cmd option on filenames from untrusted sources. If programmatic use of glob with shell command execution is necessary, ensure all filenames are thoroughly sanitized to remove shell metacharacters before execution. Monitor Red Hat advisories for an official patch release for RHTAS 1.2.2 or later. Until a fix is available, restrict permissions to prevent untrusted users from creating files processed by glob with the -c option.
Red Hat Security Advisory: RHTAS 1.2.2 - Red Hat Trusted Artifact Signer Release
Description
The RHTAS Operator can be used with OpenShift Container Platform 4.15, 4.16, 4.17, 4.18 and 4.19
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-64756 is a command injection vulnerability in the glob CLI component used by Red Hat Trusted Artifact Signer (RHTAS) versions >=1.2.0 <1.2.2. The glob CLI uses the -c/--cmd option to execute shell commands on files matching a pattern, but it fails to sanitize filenames containing shell metacharacters. This allows an attacker who can create or influence filenames processed by glob to execute arbitrary OS commands. The vulnerability is due to the shell:true parameter used in subprocess execution, which interprets shell metacharacters in filenames. Exploitation requires the attacker to have permission to create or trick the user into processing maliciously named files. The vulnerability is present in the glob CLI but not in the programmatic use of the glob package by npm. Red Hat has not yet released a patch for RHTAS but has published advisory RHSA-2026:2925 describing the issue and mitigation recommendations.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary operating system commands with the privileges of the user running the glob CLI. This can lead to unauthorized code execution, data modification or disclosure, and potential denial of service by crashing or disrupting the application. Because the commands execute in the context of the application, malicious actions may appear to originate from the application or its owner, complicating detection and attribution.
Mitigation Recommendations
Avoid using the glob CLI with the -c or --cmd option on filenames from untrusted sources. If programmatic use of glob with shell command execution is necessary, ensure all filenames are thoroughly sanitized to remove shell metacharacters before execution. Monitor Red Hat advisories for an official patch release for RHTAS 1.2.2 or later. Until a fix is available, restrict permissions to prevent untrusted users from creating files processed by glob with the -c option.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:2925
- Cve Count
- 5
- Additional Cves
- ["CVE-2025-66418","CVE-2025-66471","CVE-2026-21441","CVE-2026-24049"]
Threat ID: 6a160972e29bf47b5063a923
Added to database: 05/26/2026, 20:58:26 UTC
Last enriched: 08/17/2026, 17:59:40 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 60
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.