CVE-2026-89091

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in ansible-core. When installing a collection with `ansible-galaxy collection install`, the archive extractor validates member paths using lexical path normalisation (os.path.abspath) instead of resolving symbolic links (os.path.realpath), and it performs no containment check on symlink-typed directory members before creating them. A crafted collection tarball can chain symlink directory entries so that a subsequent file member is written outside the intended destination directory. This allows an attacker who can get a victim to install a malicious collection to overwrite arbitrary files with the privileges of the user running ansible-galaxy, leading to code execution on the control node. This is a bypass of the fix for CVE-2020-10691.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-10: 110-10
Full discourse1 post
  • Upwind Security MDR@UpwindMDR

    🚨HIGH - ansible-galaxy Collection Install Symlink Tar Escape File Overwrite (CVE-2026-89091) In ansible-core, `ansible-galaxy collection install` extracts collection tarballs without fully containing chained symlink directory entries, allowing `../`-style path escape and arbitrary file overwrite outside the target dir. A crafted collection can overwrite user-controlled files to gain code execution on the control node; this is a bypass of the CVE-2020-10691 fix. 👉Affected: ansible-core (versions not specified)

    0000045
    315 followersView on X

Explore more