{"id":"CVE-2026-89091","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-89091","summary":"A flaw was found in ansible-core. When installing a collection with\n`ansible-galaxy collection install`, the archive extractor validates member\npaths using lexical path normalisation…","details":"A flaw was found in ansible-core. When installing a collection with\n`ansible-galaxy collection install`, the archive extractor validates member\npaths using lexical path normalisation (os.path.abspath) instead of resolving\nsymbolic links (os.path.realpath), and it performs no containment check on\nsymlink-typed directory members before creating them. A crafted collection\ntarball can chain symlink directory entries so that a subsequent file member is\nwritten outside the intended destination directory. This allows an attacker who\ncan get a victim to install a malicious collection to overwrite arbitrary files\nwith the privileges of the user running ansible-galaxy, leading to code\nexecution on the control node. This is a bypass of the fix for CVE-2020-10691.","published":"2026-10-08T22:17:35.777","modified":"2026-10-08T22:17:35.777","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-89091"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2531646"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-10-08T22:17:35.777"}}