Security Flaw in Ansible Runner Leading to Potential Unrestricted File Operations
CVE-2026-103754
5.9MEDIUM
What is CVE-2026-103754?
A flaw in Ansible Runner allows for improper handling of zip archives during the extraction process. The unstream_dir() function fails to validate the targets of symbolic links extracted from the archive, enabling an attacker to create files and alter permissions in unintended directories. Specifically, this vulnerability can be exploited by crafting a malicious zip archive that influences the worker's input, resulting in unauthorized file creation or modification outside the designated directory. This security concern poses significant risks, including potential code execution on the affected systems.
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Liqiang Ji (SQUARE Research Group, Institute of Software, Chinese Academy of Sciences (ISCAS)) for reporting this issue.