Path Traversal Vulnerability in Ansible Lightspeed Model Context Protocol Server
CVE-2026-44192

6.6MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
22 July 2026

What is CVE-2026-44192?

A vulnerability exists in the Ansible Lightspeed Model Context Protocol (MCP) server that enables path traversal attacks. This flaw allows attackers to exploit indirect prompt injection, leading to unauthorized file writes to arbitrary locations on the user's system. The consequences include the potential exposure of sensitive host information and the ability for attackers to execute malicious commands, heightening the risk of complete system compromise.

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Laura Pardo (Red Hat Inc.).
.