Description
A flaw was found in ansible-core. When installing a collection with
`ansible-galaxy collection install`, the archive extractor validates member
paths using lexical path normalisation (os.path.abspath) instead of resolving
symbolic links (os.path.realpath), and it performs no containment check on
symlink-typed directory members before creating them. A crafted collection
tarball can chain symlink directory entries so that a subsequent file member is
written outside the intended destination directory. This allows an attacker who
can get a victim to install a malicious collection to overwrite arbitrary files
with the privileges of the user running ansible-galaxy, leading to code
execution on the control node. This is a bypass of the fix for CVE-2020-10691.
`ansible-galaxy collection install`, the archive extractor validates member
paths using lexical path normalisation (os.path.abspath) instead of resolving
symbolic links (os.path.realpath), and it performs no containment check on
symlink-typed directory members before creating them. A crafted collection
tarball can chain symlink directory entries so that a subsequent file member is
written outside the intended destination directory. This allows an attacker who
can get a victim to install a malicious collection to overwrite arbitrary files
with the privileges of the user running ansible-galaxy, leading to code
execution on the control node. This is a bypass of the fix for CVE-2020-10691.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 08 Oct 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in ansible-core. When installing a collection with `ansible-galaxy collection install`, the archive extractor validates member paths using lexical path normalisation (os.path.abspath) instead of resolving symbolic links (os.path.realpath), and it performs no containment check on symlink-typed directory members before creating them. A crafted collection tarball can chain symlink directory entries so that a subsequent file member is written outside the intended destination directory. This allows an attacker who can get a victim to install a malicious collection to overwrite arbitrary files with the privileges of the user running ansible-galaxy, leading to code execution on the control node. This is a bypass of the fix for CVE-2020-10691. | |
| Title | Ansible-core: ansible-core: ansible-galaxy collection install symlink path escape allows arbitrary file write / code execution | |
| First Time appeared |
Redhat
Redhat acm Redhat ansible Automation Platform Redhat ansible Core Redhat ansible Portal Redhat certifications Redhat discovery Redhat enterprise Linux Redhat migration Toolkit Applications Redhat migration Toolkit Virtualization Redhat openshift Redhat openstack Redhat rhui Redhat satellite Redhat service Mesh |
|
| Weaknesses | CWE-59 | |
| CPEs | cpe:/a:redhat:acm:2 cpe:/a:redhat:ansible_automation_platform:2 cpe:/a:redhat:ansible_core:2 cpe:/a:redhat:ansible_portal:2 cpe:/a:redhat:certifications:9 cpe:/a:redhat:discovery:2::el9 cpe:/a:redhat:migration_toolkit_applications:8 cpe:/a:redhat:migration_toolkit_virtualization:2 cpe:/a:redhat:openshift:4 cpe:/a:redhat:openstack:17.1 cpe:/a:redhat:openstack:18.0 cpe:/a:redhat:rhui:5::el9 cpe:/a:redhat:satellite:6 cpe:/a:redhat:service_mesh:3 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat acm Redhat ansible Automation Platform Redhat ansible Core Redhat ansible Portal Redhat certifications Redhat discovery Redhat enterprise Linux Redhat migration Toolkit Applications Redhat migration Toolkit Virtualization Redhat openshift Redhat openstack Redhat rhui Redhat satellite Redhat service Mesh |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
Redhat
Subscribe
Acm
Subscribe
Ansible Automation Platform
Subscribe
Ansible Core
Subscribe
Ansible Portal
Subscribe
Certifications
Subscribe
Discovery
Subscribe
Enterprise Linux
Subscribe
Migration Toolkit Applications
Subscribe
Migration Toolkit Virtualization
Subscribe
Openshift
Subscribe
Openstack
Subscribe
Rhui
Subscribe
Satellite
Subscribe
Service Mesh
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-08T21:49:30.953Z
Reserved: 2026-09-10T20:17:42.169Z
Link: CVE-2026-89091
No data.
Status : Received
Published: 2026-10-08T22:17:35.777
Modified: 2026-10-08T22:17:35.777
Link: CVE-2026-89091
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-59
Improper Link Resolution Before File Access ('Link Following')