{"id":"CVE-2026-78367","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-78367","summary":"A flaw was found in rpmbuild. When rpmbuild processes a crafted tarball in tarball mode, a specially designed tar member name can lead to macro injection. This vulnerability allows…","details":"A flaw was found in rpmbuild. When rpmbuild processes a crafted tarball in tarball mode, a specially designed tar member name can lead to macro injection. This vulnerability allows a remote attacker to execute arbitrary code on the system by convincing a user to build a malicious tarball.","published":"2026-08-24T14:17:04.767","modified":"2026-08-24T14:17:04.767","cvss":{"score":7,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-78367"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2521857"},{"type":"WEB","url":"https://github.com/rpm-software-management/rpm/issues/4314"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-24T14:17:04.767"}}