{"id":"CVE-2023-5115","aliases":["GHSA-jpvw-p8pr-9g2x","PYSEC-2026-1120"],"url":"https://o3.security/vulnerability/CVE-2023-5115","summary":"Ansible symlink attack vulnerability","details":"An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.","published":"2023-12-18T14:15:10.500Z","modified":"2026-07-07T17:56:34.211489421Z","cvss":{"score":6.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N"},"epss":{"score":0.00859,"percentile":0.56767,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"ansible","fixedVersion":"8.5.0"}],"fix":null,"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/12/msg00018.html"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2023:5701"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2023:5758"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2023-5115"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2233810"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-07T17:56:34.211489421Z"}}