{"id":"CVE-2018-10874","aliases":["GHSA-3xvg-x47j-x75w","PYSEC-2018-81"],"url":"https://o3.security/vulnerability/CVE-2018-10874","summary":"Ansible Improper Input Validation vulnerability","details":"In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result.","published":"2018-07-02T13:29:00.367Z","modified":"2026-08-07T11:31:12.328016237Z","cvss":{"score":7.8,"severity":"HIGH","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"ansible","fixedVersion":"2.4.6.0"},{"ecosystem":"PyPI","name":"ansible","fixedVersion":"2.5.6"},{"ecosystem":"PyPI","name":"ansible","fixedVersion":"2.6.1"}],"fix":null,"references":[{"type":"WEB","url":"https://usn.ubuntu.com/4072-1/"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1041396"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHBA-2018:3788"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:2150"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:2151"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:2152"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:2166"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:2321"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:2585"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:0054"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10874"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:12.328016237Z"}}