Path Traversal Vulnerability in Ansible Lightspeed Model Context Protocol Server
CVE-2026-44192
6.6MEDIUM
What is CVE-2026-44192?
A vulnerability exists in the Ansible Lightspeed Model Context Protocol (MCP) server that enables path traversal attacks. This flaw allows attackers to exploit indirect prompt injection, leading to unauthorized file writes to arbitrary locations on the user's system. The consequences include the potential exposure of sensitive host information and the ability for attackers to execute malicious commands, heightening the risk of complete system compromise.
References
CVSS V3.1
Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered by Laura Pardo (Red Hat Inc.).