Path Traversal Vulnerability in Ansible-Core Affecting Collection Install
CVE-2026-89091

8.8HIGH

What is CVE-2026-89091?

A vulnerability has been identified in ansible-core where the archive extractor, during the installation of a collection using the ansible-galaxy collection install command, improperly validates member paths. Instead of resolving symbolic links, it uses lexical path normalization. This oversight allows attackers to create crafted collection tarballs that can manipulate symlink directory entries to write files outside intended directories. If a user installs a malicious collection, it may lead to overwriting arbitrary files under the privileges of the user running ansible-galaxy, potentially resulting in unauthorized code execution on the control node. This issue circumvents the previous mitigation for a similar vulnerability.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Parameter Autonomous Pentesting Agent (parameter.ai) for reporting this issue.
.