Skip to main content
Version: v1.3.x

CVE-2026-84837

CVE Details

Visit the official vulnerability details page for CVE-2026-84837 to learn more.

Initial Publication

09/02/2026

Last Update

09/03/2026

Third Party Dependency

rpm

NIST CVE Summary

A flaw was found in rpm. An attacker can exploit a command injection vulnerability by influencing the path or filename of a tarball processed by `rpmbuild -t*` to include shell metacharacters. This is particularly relevant in automated build or continuous integration (CI) workflows that ingest externally supplied artifact names. Successful exploitation allows for arbitrary command execution with the privileges of the build user, which could lead to information disclosure or disruption of the build environment.

CVE Severity

7.8

Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

Status

Awaiting Analysis

Affected Products & Versions

VersionPaletteAIPaletteAI VerteX
1.3.2⚠️ Impacted⚠️ Impacted
1.2.2⚠️ Impacted⚠️ Impacted

Revision History

No revisions available.