<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:fleetdm:fleet:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3afleetdmfleet/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 27 Sep 2026 19:09:05 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3afleetdmfleet/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Command Injection in Fleet macOS App Manifest Generation (CVE-2026-101045)</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-101045/</link><pubDate>Sun, 27 Sep 2026 19:09:05 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-101045/</guid><description>An improper sanitization vulnerability in Fleet's macOS app install/uninstall script generator allowed arbitrary command execution as root via malicious Homebrew cask metadata.</description><content:encoded><![CDATA[<p>CVE-2026-101045 identifies a security vulnerability in the Fleet management platform's ingestion pipeline for macOS application manifests. Prior to 2026-08-19, the script generator responsible for creating install and uninstall scripts from Homebrew cask metadata failed to correctly escape shell metacharacters at all interpolation sites. This deficiency allowed an attacker capable of submitting crafted metadata to an upstream Homebrew cask to trigger arbitrary command execution as root on managed macOS hosts when the specific app was installed or uninstalled.</p>
<p>Remediation was implemented centrally in the ingestion pipeline on 2026-08-19, ensuring that all metadata is properly escaped. The fix is formally included in Fleet v4.92.0. As Fleet generates these manifests centrally and distributes them as pre-built content, no customer action was required to remediate existing environments. This vulnerability underscores the risk of automated script generation pipelines processing untrusted third-party metadata.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in arbitrary code execution with root privileges on any macOS endpoint managed by an affected Fleet installation that processes the malicious manifest. This could lead to full system compromise, exfiltration of sensitive data, or the deployment of persistent malicious agents across the managed macOS fleet.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Verify all Fleet instances are running v4.92.0 or later to ensure the patch is present in the local binary.</li>
<li>Review audit logs for any unexpected process executions originating from the Fleet agent or installer scripts on managed macOS endpoints.</li>
<li>Monitor macOS process creation logs for the execution of unexpected commands following the deployment of new or updated software packages via Fleet.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>command-injection</category><category>macos</category><category>fleet</category></item></channel></rss>