PT-2026-103842 · Red Hat · Red Hat Ansible Automation Platform 2

CVE-2026-103754

·

Publicado

2026-10-01

·

Atualizado

2026-10-01

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L
A flaw was found in ansible-runner. The unstream dir() function, which receives and extracts a streamed zip archive on the worker side of the ansible-runner transmit/worker protocol, re-creates symbolic links from archive content without validating the link target and applies chmod() and utime() to an unsanitized filesystem path derived from the archive member name. A crafted archive processed by a worker that consumes attacker-influenced input can create files, create symbolic links, or change permissions outside the intended target directory, which can be leveraged toward code execution.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-103754

Produtos afetados

Red Hat Ansible Automation Platform 2