Unknown · Rpmuncompress · CVE-2026-84838
**Name of the Vulnerable Software and Affected Versions**
rpmuncompress (affected versions not specified)
**Description**
A command injection flaw exists in rpmuncompress that allows a local attacker to execute arbitrary commands. The issue occurs when the tool processes a specially crafted archive filename containing shell metacharacters that are not properly escaped before being passed to shell command strings. Exploitation requires user interaction, such as a user or automated workflow invoking rpmuncompress on the malicious file, which can compromise the confidentiality, integrity, and availability of data accessible to the invoking user.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.