User-controlled variables inserted unescaped into shell scripts and Kubernetes manifests
Summary
| CVE | CVE-2026-71567 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat-cnalr |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-17 15:16:57 UTC |
| Updated | 2026-08-17 16:17:44 UTC |
| Description | In openshift-metal3/fakefish there is a repeated pattern in some of the scripts where shell variables are injected without quoting them either into command lines or into manifests. This mostly applies to the Image URL and BMC credentials (which are not verified by FakeFish). |
Risk And Classification
Primary CVSS: v3.1 7.7 HIGH from 74b3a70d-cca6-4d34-9789-e83b222ae3be
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
EPSS: 0.001950000 probability, percentile 0.095900000 (date 2026-08-18)
Problem Types: CWE-78 | CWE-78 CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 74b3a70d-cca6-4d34-9789-e83b222ae3be | Secondary | 7.7 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N |
| 3.1 | CNA | CVSS | 7.7 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
ChangedConfidentiality
NoneIntegrity
HighAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Openshift-metal3 | Fakefish | affected 28f9a6b git | Not specified |
| CNA | Openshift-metal3 | Fakefish | unaffected 526550a git | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/openshift-metal3/fakefish/security/advisories/GHSA-xfhv-fp7q-... | 74b3a70d-cca6-4d34-9789-e83b222ae3be | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.