Back

MEDIUM

Ansible-runner: ansible-runner: path traversal and symlink escape in unstream_dir() allows file write outside the target directory

Published Oct 1, 2026

Description

A flaw was found in ansible-runner. The unstream_dir() function, which receives and extracts a streamed zip archive on the worker side of the ansible-runner transmit/worker protocol, re-creates symbolic links from archive content without validating the link target and applies chmod() and utime() to an unsanitized filesystem path derived from the archive member name. A crafted archive processed by a worker that consumes attacker-influenced input can create files, create symbolic links, or change permissions outside the intended target directory, which can be leveraged toward code execution.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 1, 2026
Updated Oct 1, 2026
Reserved Oct 1, 2026
CISA Vulnrichment
Updated Oct 1, 2026
NVD
Status Awaiting Analysis
Modified Oct 1, 2026
Red Hat
Severity n/a
Public date n/a