A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction.
CVSS Details
- CVSS 3.1 Base Score: 4.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | Upgrade python3-tox-ansibleUpgrade ansible-dev-tools+serverUpgrade ansible-dev-environmentUpgrade automation-controller-cliUpgrade python3-pytest-ansibleUpgrade python3.12-tox-ansibleUpgrade moleculeUpgrade ansible-navigatorUpgrade ansible-lintUpgrade ansible-creatorUpgrade python3.12-pytest-ansibleUpgrade ansible-dev-toolsUpgrade python3-djangoUpgrade python3.12-django | Aug 26, 2026 | Jun 9, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub