Path Traversal Vulnerability in Pulpcore by Red Hat
CVE-2026-12701
Key Information:
What is CVE-2026-12701?
A path traversal vulnerability exists in Pulpcore, specifically in the relative_path_validator function. This function incorrectly validates content paths by only ensuring they do not start with a '/' character, thus inadequately addressing directory traversal sequences such as '../'. With this flaw, an authenticated administrator can exploit relative_path variables to incorporate traversal sequences that can navigate outside the intended export directory during FilesystemExport operations. Since the uploaded file content can also be controlled by the user, this vulnerability permits arbitrary file writes to any writable location by the Pulp service user, posing a significant risk of service compromise or enabling further system exploitation.
Affected Version(s)
Red Hat Ansible Automation Platform 2.5 for RHEL 8 0:3.49.63-2.el8ap
Red Hat Ansible Automation Platform 2.5 for RHEL 9 0:3.49.63-2.el9ap
Red Hat Ansible Automation Platform 2.6 for RHEL 9 0:3.49.63-2.el9ap
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved