
🚨HIGH - ansible-galaxy Collection Install Symlink Tar Escape File Overwrite (CVE-2026-89091) In ansible-core, `ansible-galaxy collection install` extracts collection tarballs without fully containing chained symlink directory entries, allowing `../`-style path escape and arbitrary file overwrite outside the target dir. A crafted collection can overwrite user-controlled files to gain code execution on the control node; this is a bypass of the CVE-2020-10691 fix. 👉Affected: ansible-core (versions not specified)
