Sceawere

Vulnerability Detail

CVE-2026-12545UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Hammer CLI Command Injection Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.7
Creation Date
1d ago
Vendor
Red Hat
Product
Red Hat Satellite 6.16 for RHEL 8
Attack Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Vector String
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

A flaw was found in rubygem-hammer_cli. A command injection vulnerability exists in Hammer CLI and the Railties (Ruby on Rails) component distributed with Satellite due to the insecure interpolation of the $EDITOR environment variable into the Ruby system() method. By passing a single interpolated string to system(), the application invokes a system shell (/bin/sh) that interprets shell metacharacters (e.g., ;, |, &).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.7",
  "pubDate": "2026-10-01T18:17:15.700Z",
  "pubdate": "2026-10-01T18:17:15.700Z",
  "executiveSummary": "A critical command injection vulnerability exists in rubygem-hammer_cli and the associated Railties component within Satellite.\nThe vulnerability arises from the insecure handling of the $EDITOR environment variable, which is improperly interpolated into a Ruby system() method call.\nBy manipulating the $EDITOR variable, an attacker can inject arbitrary shell metacharacters, leading to remote code execution on the underlying host.\nThis flaw affects systems where the Hammer CLI is installed and configured to invoke an external editor for data manipulation.\nThe risk implication is severe, as successful exploitation grants the attacker the ability to execute commands with the privileges of the user running the Hammer CLI process.\nAttackers can leverage this to gain unauthorized system access, exfiltrate sensitive data, or compromise the integrity of the Satellite infrastructure.\nNo specific authentication is required if the attacker can influence the environment variables of a local user or process executing the vulnerable CLI tool.",
  "technicalDetails": "The root cause of this vulnerability is the unsafe implementation of system() calls within rubygem-hammer_cli and Railties. In Ruby, passing a single string to the Kernel#system() method triggers the execution of the command through the system shell (/bin/sh).\nThe application retrieves the user's preferred text editor from the $EDITOR environment variable and concatenates it directly into the shell command string without adequate sanitization or input validation.\nBecause the shell interprets metacharacters such as semicolons (;), pipes (|), and ampersands (&), an attacker can inject malicious payloads into the $EDITOR variable. For example, setting EDITOR='vim; malicious_command' forces the shell to execute 'vim' followed by 'malicious_command'.\nThe attack flow typically follows these steps: 1. An attacker identifies a target system where the Hammer CLI is in use. 2. The attacker modifies or poisons the $EDITOR environment variable. 3. The attacker triggers a Hammer CLI operation that requires opening an editor (e.g., updating a record). 4. The vulnerable code executes system(ENV['EDITOR'] + ' ' + file). 5. The shell parses the interpolated string and executes the attacker-supplied payload alongside or instead of the intended editor binary.\nThis vulnerability is particularly dangerous because it bypasses conventional input filtering. The payload is executed with the effective permissions of the user running the CLI tool. If the tool is executed by a privileged user or a service account, the impact is magnified significantly.\nThe injection occurs at the point where the environment variable is passed to the shell; because shell execution happens implicitly, any metacharacter present in the environment variable becomes a functional command operator.\nThere is no requirement for specific network exposure if the attacker has local access to the environment where the CLI is running. However, if a web interface or secondary service facilitates the execution of Hammer CLI commands using user-controlled environment variables, the attack vector could be extended."
}
CVE-2026-12545: Hammer CLI Command Injection Vulnerability (MEDIUM Severity, CVSS: 6.7) | Sceawere