{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/rpm.org/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:rpm:rpm:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-95521"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["rpm"],"_cs_severities":["high"],"_cs_tags":["vulnerability","command-injection","supply-chain"],"_cs_type":"advisory","_cs_vendors":["RPM.org"],"content_html":"\u003cp\u003eCVE-2026-95521 is a high-severity command injection vulnerability identified in the rpm package manager. The flaw arises from insecure handling of source RPM files during installation or rebuild operations. When rpm processes a source RPM where the source or spec file basenames contain a %() macro construct, the package manager improperly invokes popen() to relocate the source file list. This execution path results in the arbitrary execution of attacker-supplied shell commands under the context of the user running the command, which may include build agents, developers, or system administrators. Because this logic is triggered by standard package processing workflows, it poses a significant risk to CI/CD pipelines and environments that ingest untrusted or third-party source packages.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary code execution on any system that processes a malicious .src.rpm file. The impact is significant for build infrastructure, development environments, and automated packaging systems, as an attacker can gain the privileges of the user running the rpm command to perform post-exploitation activities, such as credential theft or lateral movement within the build environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all systems and CI/CD runners utilizing the rpm package manager for rebuilding or installing source packages.\u003c/li\u003e\n\u003cli\u003ePrioritize patching the rpm package as soon as security updates are provided by the vendor.\u003c/li\u003e\n\u003cli\u003eImplement strict verification controls for incoming .src.rpm files from untrusted third-party sources.\u003c/li\u003e\n\u003cli\u003eAudit build logs for occurrences of unexpected subshell execution or shell metacharacters within filenames handled by rpm.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-24T14:47:26Z","date_published":"2026-09-24T14:47:26Z","id":"https://feed.craftedsignal.io/briefs/2026-09-rpm-command-injection/","summary":"A command injection vulnerability (CVE-2026-95521) in the rpm package manager allows arbitrary command execution when processing maliciously crafted source RPM files containing %() macro constructs.","title":"Command Injection in RPM Package Manager","url":"https://feed.craftedsignal.io/briefs/2026-09-rpm-command-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - RPM.org","version":"https://jsonfeed.org/version/1.1"}