REDHAT-BUG-2544510: Path Traversal

Published Oct 1, 2026
·
Updated

Reported via the ansible-security list by Liqiang Ji (ISCAS / SQUARE Research Group).

Module: src/ansiblerunner/utils/streaming.py, function unstreamdir().

unstreamdir() performs a custom ("fancy") extraction to preserve permissions and symlinks. Two defects: 1. CWE-59 (link following): a symlink member's target is read verbatim from the archive content and re-created with os.symlink() without validation, so it can point outside targetdirectory (e.g. '../outside' or an absolute path). A subsequent member extracted through that symlink lands outside targetdirectory (arbitrary write escape). 2. CWE-22 (path traversal): outpath = os.path.join(targetdirectory, info.filename) is built from the unsanitized member name. ZipFile.extract() sanitizes the arcname, but os.utime()/os.chmod() operate on the raw outpath, so a member named '../victim' changes mtime/permissions on a file outside targetdirectory.

Exploitability: in the standard AWX/AAP topology the transmit stream is produced by the trusted controller (streamdir only encodes pre-existing symlinks) and the controller->executor path is authenticated, so there this is defense-in-depth hardening. It is directly relevant to deployments that feed untrusted input into ansible-runner's Worker() path.

Upstream: https://github.com/ansible/ansible-runner Fix PR: https://github.com/ansible/ansible-runner/pull/1550 Confirmed present in 2.4.3 and devel.

Affected Software

1 affected component
Ansible ansible-runner=2.4.3

Event History

Oct 1, 2026
Data Sourced
via Red Hat·10:39 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Which deployments are most exposed?

Deployments where an untrusted party can supply or influence the transmit stream are most exposed. In the standard AWX/AAP topology, the stream is produced by a trusted controller and the controller-to-executor path is authenticated, so the issue is described as defense-in-depth hardening there.

2

What does an attacker need to exploit this?

An attacker needs control over archive member names or symlink targets in the stream processed by unstream_dir(). A crafted symlink can redirect later extraction outside the target directory, while a crafted traversal name can cause timestamp or permission changes on an external path.

3

What can be done before an update is available?

Restrict stream generation to trusted controllers and maintain authentication on the controller-to-executor path. Do not allow untrusted users or systems to provide or modify streams processed by the affected extraction routine.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203