#VU118199 OS Command Injection in foreman (Red Hat package) - CVE-2025-10622
Published: November 7, 2025
foreman (Red Hat package)
Red Hat Inc.
Description
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation passed via the ct_location and fcct_location parameters. A remote privileged user can pass specially crafted data to the application and execute arbitrary OS commands on the target system.