A vulnerability was discovered in rpmbuild where processing a crafted tarball in tarball mode can lead to macro injection via specially designed tar member names. This flaw allows a remote attacker to execute arbitrary code on the affected system. The attack vector requires social engineering, convincing a user to build a malicious tarball. The vulnerability is tracked as CVE-2026-78367 and has been reported to Red Hat's security team. References include Red Hat's security advisory, a Bugzilla bug report, and a GitHub issue in the rpm-software-management repository. The issue affects the RPM build toolchain, which is widely used in Linux distributions such as Red Hat Enterprise Linux and Fedora. Given its potential for remote code execution, this vulnerability is considered high severity.