CVE-2026-89091: Ansible-core: ansible-core: ansible-galaxy collection install symlink path escape allows arbitrary file write / code execution
A flaw was found in ansible-core. When installing a collection with ansible-galaxy collection install, the archive extractor validates member paths using lexical path normalisation (os.path.abspath) instead of resolving symbolic links (os.path.realpath), and it performs no containment check on symlink-typed directory members before creating them. A crafted collection tarball can chain symlink directory entries so that a subsequent file member is written outside the intended destination directory. This allows an attacker who can get a victim to install a malicious collection to overwrite arbitrary files with the privileges of the user running ansible-galaxy, leading to code execution on the control node. This is a bypass of the fix for CVE-2020-10691.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users who run ansible-galaxy collection install and can be induced to install a crafted collection are exposed. The impact is on the control node, where files can be overwritten with the privileges of the user running ansible-galaxy.
What does an attacker need to exploit it?
The attacker needs to provide a malicious collection tarball and persuade a victim to install it with ansible-galaxy collection install. No existing privileges are required, but user interaction is required.
What can happen if exploitation succeeds?
A crafted archive can use chained symbolic-link directory entries to cause a later file to be written outside the selected collection destination. This can overwrite arbitrary files accessible to the ansible-galaxy user and lead to code execution on the control node.
Is this related to an earlier Ansible collection-install vulnerability?
Yes. The issue is described as a bypass of the fix for CVE-2020-10691.