CVE-2026-103754
Awaiting Analysis Awaiting Analysis - Queue

ansible-runner Path Traversal via Symbolic Links

Vulnerability report for CVE-2026-103754, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: redhat-SADP

Description

A flaw was found in ansible-runner. The unstream_dir() function, which receives and extracts a streamed zip archive on the worker side of the ansible-runner transmit/worker protocol, re-creates symbolic links from archive content without validating the link target and applies chmod() and utime() to an unsanitized filesystem path derived from the archive member name. A crafted archive processed by a worker that consumes attacker-influenced input can create files, create symbolic links, or change permissions outside the intended target directory, which can be leveraged toward code execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redhat ansible-runner 2.4.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in ansible-runner's unstream_dir() function which processes streamed zip archives. It recreates symbolic links without validating their targets and applies file operations to unsanitized paths from archive names. A crafted archive can create files, symlinks, or change permissions outside the intended directory, potentially leading to code execution.

Detection Guidance
  • Check ansible-runner version for affected releases (e.g., 2.4.3 or development branches) using: ansible-runner --version
  • Monitor for unexpected file creation or permission changes in ansible-runner target directories
  • Inspect logs for extraction errors from unstream_dir() function failures
  • Review pull request #1550 on ansible-runner GitHub for patched versions
Impact Analysis

An attacker could exploit this to write files or modify permissions outside the intended directory. This could lead to arbitrary code execution if malicious files are created in system directories. The risk is higher when ansible-runner processes untrusted input rather than trusted controller data.

Compliance Impact

This vulnerability could potentially violate compliance with GDPR and HIPAA by allowing unauthorized file creation, permission changes, or symbolic link manipulation outside intended directories. Such actions may lead to unauthorized data access, modification, or disclosure, which are key concerns under these regulations.

Mitigation Strategies

Apply the patch from ansible-runner pull request #1550 to fix the unstream_dir() function. Avoid processing untrusted zip archives in ansible-runner until patched. Monitor ansible-runner versions and update to the latest secure release.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103754. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart