CVE-2020-10691(redhat / ansible_engine)

LOWCVSS 5.2 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. An attacker could take advantage to overwrite any file within the system.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ansible_engine
  • ansible_tower

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Vendors
Products
ansible_engineansible_tower

1 version affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-10: 110-10
Full discourse1 post
  • Upwind Security MDR@UpwindMDR

    🚨HIGH - ansible-galaxy Collection Install Symlink Tar Escape File Overwrite (CVE-2026-89091) In ansible-core, `ansible-galaxy collection install` extracts collection tarballs without fully containing chained symlink directory entries, allowing `../`-style path escape and arbitrary file overwrite outside the target dir. A crafted collection can overwrite user-controlled files to gain code execution on the control node; this is a bypass of the CVE-2020-10691 fix. 👉Affected: ansible-core (versions not specified)

    0000045
    315 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appredhatansible_engine---
Appredhatansible_tower3.0--

Explore more