Description
Ansible FreeBSD Jail Connection Plugin is an Ansible connection plugin for FreeBSD Jails via jexec. Through version 1.3.0, the jailexec connection plugin's put_file resolved a transfer's destination to a path on the jail host ( + ) and ran mkdir -p and mv there as root on the host. Those commands follow symbolic links, and the path was operated on outside the jail, so a symlink existing inside the jail was followed by the host-side, root-privileged mv. A party controlling content inside a managed jail (the jail's root, or any process able to create a symlink in a directory an Ansible task later writes to) can therefore cause an arbitrary root-owned write on the host, outside the jail — a full jail escape. Arbitrary root-owned host writes are readily escalated to host compromise (e.g. cron, rc.d, authorized_keys). Preconditions for this vulnerability are that the operator runs a copy/template/fetch-style task (anything using put_file) against the jail, and the attacker can place a symlink inside the jail at or above the task's destination before the transfer runs. This issue has been fixed in version 2.0.0.
Published: 2026-09-21
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution via jail escape
Action: Patch immediately
AI Analysis

Impact

The Ansible FreeBSD Jail Connection Plugin processes transferred files by executing mkdir and mv as root on the host side. These commands follow symbolic links without containment checks, allowing a provider who can create a symlink in the jail to force the host‑side move to write outside the jail. The result is an arbitrary root‑privileged write on the host filesystem, which can be leveraged to install malware, modify system configuration, or compromise SSH keys, effectively granting full host control. This weakness is CWE‑59, representing an insecure path traversal via symlink following.

Affected Systems

Deployments that use the chofstede:ansible_jailexec plugin before version 2.0.0, notably versions up to 1.3.0 and earlier. The vulnerability is triggered when Ansible performs copy, template, fetch or any put_file operation against a FreeBSD jail and the attacker can place a symlink at or above the destination path inside the jail at the time of transfer.

Risk and Exploitability

The CVSS score of 8.2 indicates high severity, and the vulnerability is not currently listed in the CISA KEV catalog. No EPSS data is available, so the estimated exploitation probability is unknown, but the requirement of host‑side root privileges and the ability to inject arbitrary files make it a high‑risk local privilege escalation scenario. The attack vector is local to the environment that runs the vulnerable plugin; an attacker must control or influence content inside the jail to place the symlink. Once executed, the host can be fully compromised. Because the issue is fixed in v2.0.0, timely patching is essential to mitigate risk.

Generated by OpenCVE AI on September 21, 2026 at 16:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade chofstede:ansible_jailexec to version 2.0.0 or later, which removes the host‑side symlink traversal during put_file operations.
  • If an upgrade is not feasible, disable the use of put_file, copy, template, and fetch modules against the target jail until a fix is in place, or restrict the injector process to a non‑root user to prevent host‑side root writes.
  • Enforce filesystem permissions or ACLs inside the FreeBSD jail so that only trusted users can create symlinks in directories used by Ansible, thereby preventing malicious link creation.

Generated by OpenCVE AI on September 21, 2026 at 16:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-cxgv-hp74-jj7r Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)
History

Mon, 21 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Chofstede
Chofstede ansible Jailexec
Vendors & Products Chofstede
Chofstede ansible Jailexec

Mon, 21 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Ansible FreeBSD Jail Connection Plugin is an Ansible connection plugin for FreeBSD Jails via jexec. Through version 1.3.0, the jailexec connection plugin's put_file resolved a transfer's destination to a path on the jail host ( + ) and ran mkdir -p and mv there as root on the host. Those commands follow symbolic links, and the path was operated on outside the jail, so a symlink existing inside the jail was followed by the host-side, root-privileged mv. A party controlling content inside a managed jail (the jail's root, or any process able to create a symlink in a directory an Ansible task later writes to) can therefore cause an arbitrary root-owned write on the host, outside the jail — a full jail escape. Arbitrary root-owned host writes are readily escalated to host compromise (e.g. cron, rc.d, authorized_keys). Preconditions for this vulnerability are that the operator runs a copy/template/fetch-style task (anything using put_file) against the jail, and the attacker can place a symlink inside the jail at or above the task's destination before the transfer runs. This issue has been fixed in version 2.0.0.
Title Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)
Weaknesses CWE-59
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Chofstede Ansible Jailexec
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T15:44:36.603Z

Reserved: 2026-06-16T14:33:35.710Z

Link: CVE-2026-55074

cve-icon Vulnrichment

Updated: 2026-09-21T15:44:29.901Z

cve-icon NVD

Status : Deferred

Published: 2026-09-21T15:17:29.627

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-55074

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:23:35Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')