Path Traversal Vulnerability in Ansible-Core Affecting Collection Install
CVE-2026-89091
What is CVE-2026-89091?
A vulnerability has been identified in ansible-core where the archive extractor, during the installation of a collection using the ansible-galaxy collection install command, improperly validates member paths. Instead of resolving symbolic links, it uses lexical path normalization. This oversight allows attackers to create crafted collection tarballs that can manipulate symlink directory entries to write files outside intended directories. If a user installs a malicious collection, it may lead to overwriting arbitrary files under the privileges of the user running ansible-galaxy, potentially resulting in unauthorized code execution on the control node. This issue circumvents the previous mitigation for a similar vulnerability.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved