A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade ansible-coreUpgrade ansible-test | Jun 23, 2026 | Jun 5, 2026 |
| Debian | — | Upgrade ansibleUpgrade ansible-core | Jun 8, 2026 | Jun 8, 2026 |
| Redhat_linux | — | Upgrade ansible-testUpgrade ansible-core | Jul 17, 2026 | Jun 5, 2026 |
| Rocky_linux | — | Upgrade ansible-testUpgrade ansible-core | Aug 24, 2026 | Aug 20, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jun 17, 2026 | Jun 5, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub