Description
A flaw was found in ansible-runner. The unstream_dir() function, which receives and extracts a streamed zip archive on the worker side of the ansible-runner transmit/worker protocol, re-creates symbolic links from archive content without validating the link target and applies chmod() and utime() to an unsanitized filesystem path derived from the archive member name. A crafted archive processed by a worker that consumes attacker-influenced input can create files, create symbolic links, or change permissions outside the intended target directory, which can be leveraged toward code execution.
Published: 2026-10-01
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

The vulnerability exposes an insecure extraction routine within ansible‑runner’s unstream_dir() function. When the component processes a streamed ZIP archive provided by a worker, it recreates symbolic links and applies file permissions based on identical archive member names without validating the link target or sanitizing the resulting file path. A crafted archive can therefore create files, symlinks, or modify permissions at locations outside the intended target directory. This path traversal and symlink escape capability enables an attacker to write arbitrary files or alter system files, which can ultimately lead to execution of malicious code on the machine hosting the ansible‑runner worker.

Affected Systems

The flaw affects any installation that includes Red Hat Ansible Automation Platform 2, specifically the ansible‑runner component. No specific sub‑versions are listed, so all deployments that rely on this product are potentially impacted.

Risk and Exploitability

The CVSS score of 5.9 indicates a moderate severity risk. The EPSS score is unavailable and the vulnerability is not present in the CISA KEV catalog, suggesting that exploit activity is currently limited. The likely attack vector involves an attacker who can supply a crafted ZIP archive to an ansible‑runner worker over the transmit/worker protocol; the worker then extracts the archive with its operating system privileges. Successful exploitation can result in arbitrary file creation or permission changes that may give the attacker a foothold for code execution on the host.

Generated by OpenCVE AI on October 1, 2026 at 13:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Red Hat Ansible Automation Platform to a version that contains the fix for CVE‑2026‑103754.
  • Run the ansible‑runner worker in a sandboxed or containerized environment with the least privileges and restrict the worker’s filesystem view so that even if the archive tries to escape, no files outside the intended directory can be affected.
  • Validate archive members before extraction – reject or normalize any paths that are absolute or contain relative components that could escape the target directory, and consider disabling symbolic‑link creation during extraction.

Generated by OpenCVE AI on October 1, 2026 at 13:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 12:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in ansible-runner. The unstream_dir() function, which receives and extracts a streamed zip archive on the worker side of the ansible-runner transmit/worker protocol, re-creates symbolic links from archive content without validating the link target and applies chmod() and utime() to an unsanitized filesystem path derived from the archive member name. A crafted archive processed by a worker that consumes attacker-influenced input can create files, create symbolic links, or change permissions outside the intended target directory, which can be leveraged toward code execution.
Title Ansible-runner: ansible-runner: path traversal and symlink escape in unstream_dir() allows file write outside the target directory
First Time appeared Redhat
Redhat ansible Automation Platform
Weaknesses CWE-22
CPEs cpe:/a:redhat:ansible_automation_platform:2
Vendors & Products Redhat
Redhat ansible Automation Platform
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L'}


Subscriptions

Redhat Ansible Automation Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-01T13:20:30.126Z

Reserved: 2026-10-01T10:32:25.691Z

Link: CVE-2026-103754

cve-icon Vulnrichment

Updated: 2026-10-01T13:20:25.955Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-01T12:17:15.937

Modified: 2026-10-01T14:17:28.570

Link: CVE-2026-103754

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T14:00:10Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')