Path Traversal Vulnerability in AWX CLI Tool by Red Hat
CVE-2026-52902
4.7MEDIUM
What is CVE-2026-52902?
A vulnerability exists in the AWX CLI tool (awxkit) that can be exploited through a path traversal flaw within the YAML !include directive. This issue allows an attacker to create a malicious YAML file capable of reading arbitrary YAML-formatted files from the local filesystem when imported using the command 'awx --conf.format yaml import'. Since the vulnerability relies on user interaction for exploitation, it poses significant risks if users are unaware of the potential threats from uncontrolled YAML imports.