GHSA-79jg-9wx4-f5rrMediumCVSS 5.3

A flaw was found in Foreman. The foreman-tail utility is vulnerable to OS command injection due...

Published
October 1, 2026
Last Modified
October 2, 2026

🔗 CVE IDs covered (1)

📋 Description

A flaw was found in Foreman. The foreman-tail utility is vulnerable to OS command injection due to the unsafe use of the eval command. The script takes user-supplied arguments and incorporates them directly into a string that is then executed by eval to expand file paths. Because the input is not sanitized or quoted, a local attacker can inject shell metacharacters (e.g., ;, &, |) to execute arbitrary system commands.

🔗 References (8)