No advisories yet.
Solution
No solution given by the vendor.
Workaround
The following practices would help for avoiding exposure and mitigate this flaw: 1. Ensure that GALAXY_ENABLE_LEGACY_ROLES is set to False (the default) in your Galaxy/Hub configuration. This prevents the v1 API routes from being registered, making the vulnerable endpoint entirely unreachable. 2. If legacy role support must be enabled, restrict access to the Galaxy/Hub API to trusted users only. The vulnerability requires authentication, so limiting who can authenticate reduces exposure. 3. Monitor import activity for suspicious git references containing shell metacharacters in branch or tag names.
Tue, 16 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 16 Jun 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A command injection vulnerability was found in galaxy_ng. The do_git_checkout() function in the legacy role import API (v1) interpolates unsanitized git ref names (branch/tag names) into shell commands executed via subprocess.run() with shell=True. An authenticated user who controls a git repository can create a branch or tag with shell metacharacters in the name to achieve remote code execution on the pulp worker. The vulnerable endpoint is only reachable when GALAXY_ENABLE_LEGACY_ROLES is set to True, which is not the default configuration. | |
| Title | Galaxy_ng: shell injection in legacy role import via unsanitized git ref names | |
| First Time appeared |
Redhat
Redhat ansible Automation Platform |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:/a:redhat:ansible_automation_platform:2 | |
| Vendors & Products |
Redhat
Redhat ansible Automation Platform |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-06-16T16:07:02.819Z
Reserved: 2026-06-16T13:22:54.012Z
Link: CVE-2026-12398
Updated: 2026-06-16T16:06:32.657Z
Status : Awaiting Analysis
Published: 2026-06-16T15:16:36.103
Modified: 2026-06-16T15:26:04.250
Link: CVE-2026-12398
No data.
OpenCVE Enrichment
No data.