{"id":"CVE-2026-11332","aliases":["PYSEC-2026-3458"],"url":"https://o3.security/vulnerability/CVE-2026-11332","summary":"ansible-core: Argument injection in ansible-galaxy role install leads to arbitrary code execution","details":"A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.","published":"2026-06-05T09:33:46Z","modified":"2026-07-23T15:11:38.566563365Z","cvss":{"score":7.8,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"ansible-core","fixedVersion":"2.16.19rc1"},{"ecosystem":"PyPI","name":"ansible-core","fixedVersion":"2.18.18rc1"},{"ecosystem":"PyPI","name":"ansible-core","fixedVersion":"2.19.11rc1"},{"ecosystem":"PyPI","name":"ansible-core","fixedVersion":"2.20.7rc1"},{"ecosystem":"PyPI","name":"ansible-core","fixedVersion":"2.21.1rc1"}],"fix":{"url":"https://github.com/ansible/ansible/pull/87070","label":"ansible/ansible#87070"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-11332"},{"type":"WEB","url":"https://github.com/ansible/ansible/pull/87070"},{"type":"WEB","url":"https://github.com/ansible/ansible/commit/edee59aa15abcc74d920bb3e9c3835ab8db05a2f"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-11332"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2485379"},{"type":"PACKAGE","url":"https://github.com/ansible/ansible"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11332.json"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-23T15:11:38.566563365Z"}}