PT-2026-97498 · Red Hat · Red Hat Ansible Automation Platform 2+5
CVSS v3.1
3.1
Low
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
The product name cannot be determined (affected versions not specified)
Description
A validation gap exists in the
LaunchConfigurationBaseSerializer.scm branch where the validate scm branch() check for leading dashes is missing. This allows the scm branch variable to accept malicious input, such as --upload-pack=/bin/id. While a defense-in-depth check in jobs.py:1502 currently prevents execution by raising a ValueError, the lack of API-level validation means the system relies solely on a task-layer guard. If this guard is removed or refactored, it could lead to Remote Code Execution (RCE), a situation where an attacker can execute arbitrary commands on the host machine.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat Ansible Automation Platform 2
Red Hat Ansible Automation Platform 2.5 For Rhel 8
Red Hat Ansible Automation Platform 2.5 For Rhel 9
Red Hat Ansible Automation Platform 2.6
Red Hat Ansible Automation Platform 2.6 For Rhel 9
Red Hat Ansible Automation Platform 2.7