CVE-2026-89091 — A flaw was found in ansible-core.
Description
A flaw was found in ansible-core. When installing a collection with `ansible-galaxy collection install`, the archive extractor validates member paths using lexical path normalisation (os.path.abspath) instead of resolving symbolic links (os.path.realpath), and it performs no containment check on symlink-typed directory members before creating them. A crafted collection tarball can chain symlink directory entries so that a subsequent file member is written outside the intended destination directory. This allows an attacker who can get a victim to install a malicious collection to overwrite arbitrary files with the privileges of the user running ansible-galaxy, leading to code execution on the control node. This is a bypass of the fix for CVE-2020-10691.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HHigh severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
PR
None
Privileges Required
UI
Required
User Interaction
S
Unchanged
Scope
C
High
Confidentiality
I
High
Integrity
A
High
Availability
References
Related threats
same CWE or vendorCVE-2026-107716 — Banks generates meaningful LLM prompts using a simple template language.
CVE-2026-107716 · 2h ago
CVE-2026-107707 — Intego Antivirus for Windows through 3.0.0.1 contains a link following vulnerability in its optimization module that allows local unprivileged user…
CVE-2026-107707 · 4h ago
CVE-2026-107608 — Improper link resolution before file access in the asset bundling output handling in AWS aws-cdk-lib before 2.267.0 might allow a context-dependent…
CVE-2026-107608 · 4h ago
CVE-2026-107578 — Improper link resolution and external control of file paths in the administrative command-line operations of hMailServer.exe in Progressive Robot h…
CVE-2026-107578 · 12h ago
CVE-2026-106508 — Backstage is an open framework for building developer portals.
CVE-2026-106508 · 2d ago
CVE-2026-106507 — Backstage is an open framework for building developer portals.
CVE-2026-106507 · 2d ago