VDB

RHSA-2026%3A2925

RHSA-2026%3A2925 PUBLISHED CVSS 7.099999904632568 HIGH

A flaw was found in glob. This vulnerability allows arbitrary command execution via processing files with malicious names when the glob command-line interface (CLI) is used with the -c/--cmd option, enabling shell metacharacters to trigger command injection.

Risk Scores

CVSS 3.1
7.099999904632568
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

Affected Products

VendorProductVersions
isaacsnode-glob
Red HatRed Hat Trusted Artifact Signer
Red Hatregistry.redhat.io/rhtas/segment-reporting-rhel9@sha256:433385e5a9d3524baea007bf67ea785b2ee76b8218debf21fedf935950ab284e_amd64 as a component of Red Hat Trusted Artifact Signer 1.2*, *, registry.redhat.io/rhtas/segment-reporting-rhel9@sha256:433385e5a9d3524baea007bf67ea785b2ee76b8218debf21fedf935950ab284e_amd64
Red Hatregistry.redhat.io/rhtas/segment-reporting-rhel9@sha256:433385e5a9d3524baea007bf67ea785b2ee76b8218debf21fedf935950ab284e_amd64 as a component of Red Hat Trusted Artifact Signer 1.2*, registry.redhat.io/rhtas/segment-reporting-rhel9@sha256:433385e5a9d3524baea007bf67ea785b2ee76b8218debf21fedf935950ab284e_amd64, registry.redhat.io/rhtas/segment-reporting-rhel9@sha256:433385e5a9d3524baea007bf67ea785b2ee76b8218debf21fedf935950ab284e_amd64
Red Hatregistry.redhat.io/rhtas/segment-reporting-rhel9@sha256:433385e5a9d3524baea007bf67ea785b2ee76b8218debf21fedf935950ab284e_amd64 as a component of Red Hat Trusted Artifact Signer 1.2

Timeline

  • Feb 18, 2026 CVE Published
  • Aug 28, 2026 CVE Updated
  • Aug 28, 2026 Distribution Patch
  • Aug 28, 2026 Distribution Patch
  • Aug 28, 2026 Security Advisory
  • Aug 28, 2026 Security Advisory
  • Aug 28, 2026 Security Advisory
  • Aug 28, 2026 Security Advisory
  • Aug 28, 2026 Security Advisory
  • Aug 28, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›