A vulnerability was found in Foreman. It has been declared as critical. Affected is an unknown function of the component Transpiler Command Handler. The manipulation of the argument ct_location/fcct_location results in os command injection.

This vulnerability is identified as CVE-2025-10622. The attack can only be performed from the local network. There is not any exploit available.