Vendor
A command injection vulnerability (CVE-2026-95521) in the rpm package manager allows arbitrary command execution when processing maliciously crafted source RPM files containing %() macro constructs.