<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:redhat:ansible_tower:3.0:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aredhatansible_tower3.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 09 Oct 2026 00:27:59 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aredhatansible_tower3.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Arbitrary File Write in ansible-core via Malicious Collection Installation</title><link>https://feed.craftedsignal.io/briefs/2026-10-ansible-core-traversal/</link><pubDate>Fri, 09 Oct 2026 00:27:59 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-ansible-core-traversal/</guid><description>A path traversal vulnerability in ansible-core allows attackers to execute arbitrary code on a control node by distributing a crafted collection tarball that bypasses symlink validation.</description><content:encoded><![CDATA[<p>CVE-2026-89091 describes a critical path traversal vulnerability within the ansible-core archive extraction process. During the execution of 'ansible-galaxy collection install', the system performs lexical path normalization via 'os.path.abspath' but fails to resolve symbolic links or conduct containment checks before processing directory members within a tarball. An attacker can construct a malicious collection containing chained symlink directory entries that point outside the intended installation path. When an unsuspecting user installs the collection, the extraction process follows these symlinks and overwrites arbitrary files on the local filesystem. Because 'ansible-galaxy' typically runs with the permissions of the invoking user, this flaw enables arbitrary file write, which can be leveraged to achieve code execution on the control node. This vulnerability represents a regression or bypass of the mitigations previously introduced for CVE-2020-10691. Organizations should prioritize updating ansible-core to the vendor-patched release.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows a malicious actor to overwrite critical files on the system running 'ansible-galaxy'. If the victim is a privileged user or service account, the attacker can achieve persistent code execution on the control node, potentially leading to full compromise of the automation environment and subsequent lateral movement across the infrastructure managed by Ansible.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Patch ansible-core to the latest version provided by Red Hat that addresses CVE-2026-89091.</li>
<li>Audit build pipelines and CI/CD runners to ensure only collections from trusted, verified sources are installed.</li>
<li>Restrict the permissions of accounts authorized to run 'ansible-galaxy collection install' to minimize the impact of potential file overwrite attacks.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>code-execution</category><category>path-traversal</category></item></channel></rss>