Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-12398— Galaxy_ng: shell injection in legacy role import via unsanitized git ref names

Quick assessment

Affected
Red Hat Red Hat Ansible Automation Platform 2
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Galaxy NG是美国Ansible公司开源的新一代后端服务。 Ansible Galaxy NG存在命令注入漏洞,该漏洞源于galaxy_ng中do_git_checkout()函数将未经过清理的git ref名称插入shell命令,可能导致经过身份验证的用户通过创建包含shell元字符的分支或标签实现在pulp worker上远程执行代码。

CVSS 7.5 · High EPSS 0.89% · P58

Affected Version Matrix 9

VendorProduct Version RangeStatus
Red Hat Red Hat Ansible Automation Platform 2 any unaffected
any affected
any affected
any affected
any affected
any unknown
any unknown
any unknown
… +1 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-12398

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Galaxy_ng: shell injection in legacy role import via unsanitized git ref names
Source: CVE Program / CVE List V5
Vulnerability Description
A command injection vulnerability was found in galaxy_ng. The do_git_checkout() function in the legacy role import API (v1) interpolates unsanitized git ref names (branch/tag names) into shell commands executed via subprocess.run() with shell=True. An authenticated user who controls a git repository can create a branch or tag with shell metacharacters in the name to achieve remote code execution on the pulp worker. The vulnerable endpoint is only reachable when GALAXY_ENABLE_LEGACY_ROLES is set to True, which is not the default configuration.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Source: CVE Program / CVE List V5
Vulnerability Title
Ansible Galaxy NG 命令注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Galaxy NG是美国Ansible公司开源的新一代后端服务。 Ansible Galaxy NG存在命令注入漏洞,该漏洞源于galaxy_ng中do_git_checkout()函数将未经过清理的git ref名称插入shell命令,可能导致经过身份验证的用户通过创建包含shell元字符的分支或标签实现在pulp worker上远程执行代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2

II. Public POCs for CVE-2026-12398

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-12398

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-12398 (1)

Other References for CVE-2026-12398 (1)

Same Patch Batch · Red Hat · 2026-06-16 · 7 CVEs total

CVE-2026-10649 8.6 HIGH Pacemaker: pacemaker: denial of service via integer overflow in remote message decompressi
CVE-2026-1767 5.6 MEDIUM Localsearch: tracker-miners: gnome localsearch mp3 extractor: heap buffer overflow leading
CVE-2026-1766 5.6 MEDIUM Localsearch: tracker-miners: gnome localsearch mp3 extractor: denial of service and inform
CVE-2026-1765 5.6 MEDIUM Localsearch: tracker-miners: gnome localsearch mp3 extractor: denial of service and potent
CVE-2026-1764 5.6 MEDIUM Localsearch: tracker-miners: gnome localsearch mp3 extractor: heap buffer overflow leads t
CVE-2026-4367 5.5 MEDIUM Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing

IV. Related Vulnerabilities

V. Comments for CVE-2026-12398

No comments yet


Leave a comment