Sceawere
Vulnerability Detail
CVE-2026-101045UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Fleet Cask Metadata Command Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8
- Creation Date
- 14h ago
- Vendor
- fleetdm
- Product
- fleet
- Attack Type
- Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Fleet-maintained app install and uninstall scripts for macOS are generated from Homebrew cask metadata. In manifests generated before 2026-08-19, the script generator escaped this metadata at some interpolation sites but not all of them, so cask metadata containing shell metacharacters (for example $(...) command substitution) could be carried into scripts that execute as root on managed macOS hosts. An attacker who could land crafted metadata in an upstream Homebrew cask — without needing any Fleet credentials — could achieve arbitrary command execution as root on managed macOS hosts that install or uninstall the affected Fleet-maintained app; exploitation required the crafted metadata to pass both upstream Homebrew cask review and Fleet's review of the automated ingestion pull request. The fix (fleetdm/fleet#51324) landed in Fleet's ingestion pipeline on 2026-08-19 so that all manifests generated on or after that date escape cask metadata at every interpolation site; because manifests are generated centrally and distributed as pre-built content, remediation applied to all deployments with no customer action, and the code fix is included in Fleet v4.92.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.0",
"pubDate": "2026-09-27T18:16:30.897Z",
"pubdate": "2026-09-27T18:16:30.897Z",
"executiveSummary": "A command injection vulnerability existed within the Fleet-maintained application management system, specifically affecting the automated script generation pipeline for macOS Homebrew casks.\nThe vulnerability stemmed from improper sanitization of upstream Homebrew cask metadata during the script generation process. Because these scripts are executed with root privileges on managed macOS hosts, an attacker successfully injecting malicious shell metacharacters into the metadata could achieve arbitrary command execution.\nThe exploit required the successful placement of crafted metadata within an upstream Homebrew cask, which then had to pass both upstream maintainer review and Fleet's automated ingestion and pull request validation process.\nThe risk was centrally mitigated by Fleet through an update to the ingestion pipeline on 2026-08-19, which enforced strict escaping of metadata at all interpolation sites. This patch, included in Fleet v4.92.0, effectively closed the injection vector across all deployments without requiring customer-side remediation actions.",
"technicalDetails": "The vulnerability originated in the logic responsible for translating Homebrew cask metadata into executable shell scripts for macOS application lifecycle management. The generator failed to consistently apply shell escaping mechanisms at all interpolation sites within the generated scripts.\nThe root cause is a classic improper neutralization of special elements used in an OS command (CWE-78). By embedding shell metacharacters—specifically command substitution sequences such as $(...)—into fields that were subsequently processed by the script generator, an attacker could force the shell to execute arbitrary code.\nThe attack flow required a multi-stage approach. First, an attacker must commit malicious metadata to an upstream Homebrew cask repository. Second, the metadata had to evade both the upstream repository's review process and Fleet's internal ingestion validation logic. If successfully ingested, the malicious metadata would be embedded into the installation or uninstallation scripts distributed to managed endpoints.\nWhen a Fleet-managed macOS host executed the compromised script, the shell would evaluate the malicious command substitution within the context of the script's execution. Since Fleet-managed installation scripts typically run with root privileges to modify system state, the payload would execute with full administrative rights, leading to a complete compromise of the affected endpoint.\nThe vulnerable component is the centralized script generation and ingestion pipeline. All manifests generated prior to 2026-08-19 were susceptible to this injection vector. The vulnerability was inherently local to the host where the script was executed, but the vector was delivery-based via the centralized management platform.\nExploitation required no authentication against Fleet itself, relying instead on the trust model established during the metadata ingestion phase. By targeting the upstream supply chain, an attacker could achieve remote code execution across an entire fleet of managed devices that pull the compromised package manifest.\nThe remediation, identified as fleetdm/fleet#51324, standardized the escaping logic across all interpolation points, ensuring that input metadata is strictly treated as data rather than executable shell syntax regardless of the content of the cask attributes."
}