A flaw was found in ansible-core. When installing a collection with
`ansible-galaxy collection install`, the archive extractor validates member
paths using lexical path normalisation (os.path.abspath) instead of resolving
symbolic links (os.path.realpath), and it performs no containment check on
symlink-typed directory members before creating them. A crafted collection
tarball can chain symlink directory entries so that a subsequent file member is
written outside the intended destination directory. This allows an attacker who
can get a victim to install a malicious collection to overwrite arbitrary files
with the privileges of the user running ansible-galaxy, leading to code
execution on the control node. This is a bypass of the fix for CVE-2020-10691.

Project Subscriptions

Vendors Products
Ansible Automation Platform Subscribe
Ansible Core Subscribe
Ansible Portal Subscribe
Certifications Subscribe
Discovery Subscribe
Enterprise Linux Subscribe
Migration Toolkit Applications Subscribe
Migration Toolkit Virtualization Subscribe
Openshift Subscribe
Openstack Subscribe
Satellite Subscribe
Service Mesh Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 08 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in ansible-core. When installing a collection with `ansible-galaxy collection install`, the archive extractor validates member paths using lexical path normalisation (os.path.abspath) instead of resolving symbolic links (os.path.realpath), and it performs no containment check on symlink-typed directory members before creating them. A crafted collection tarball can chain symlink directory entries so that a subsequent file member is written outside the intended destination directory. This allows an attacker who can get a victim to install a malicious collection to overwrite arbitrary files with the privileges of the user running ansible-galaxy, leading to code execution on the control node. This is a bypass of the fix for CVE-2020-10691.
Title Ansible-core: ansible-core: ansible-galaxy collection install symlink path escape allows arbitrary file write / code execution
First Time appeared Redhat
Redhat acm
Redhat ansible Automation Platform
Redhat ansible Core
Redhat ansible Portal
Redhat certifications
Redhat discovery
Redhat enterprise Linux
Redhat migration Toolkit Applications
Redhat migration Toolkit Virtualization
Redhat openshift
Redhat openstack
Redhat rhui
Redhat satellite
Redhat service Mesh
Weaknesses CWE-59
CPEs cpe:/a:redhat:acm:2
cpe:/a:redhat:ansible_automation_platform:2
cpe:/a:redhat:ansible_core:2
cpe:/a:redhat:ansible_portal:2
cpe:/a:redhat:certifications:9
cpe:/a:redhat:discovery:2::el9
cpe:/a:redhat:migration_toolkit_applications:8
cpe:/a:redhat:migration_toolkit_virtualization:2
cpe:/a:redhat:openshift:4
cpe:/a:redhat:openstack:17.1
cpe:/a:redhat:openstack:18.0
cpe:/a:redhat:rhui:5::el9
cpe:/a:redhat:satellite:6
cpe:/a:redhat:service_mesh:3
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat acm
Redhat ansible Automation Platform
Redhat ansible Core
Redhat ansible Portal
Redhat certifications
Redhat discovery
Redhat enterprise Linux
Redhat migration Toolkit Applications
Redhat migration Toolkit Virtualization
Redhat openshift
Redhat openstack
Redhat rhui
Redhat satellite
Redhat service Mesh
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-08T21:49:30.953Z

Reserved: 2026-09-10T20:17:42.169Z

Link: CVE-2026-89091

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T22:17:35.777

Modified: 2026-10-08T22:17:35.777

Link: CVE-2026-89091

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses