GHSA-w8p5-mx5w-cpqjHighCVSS 7.8

ansible-core: Argument injection in ansible-galaxy role install leads to arbitrary code execution

Published
June 5, 2026
Last Modified
July 16, 2026

🔗 CVE IDs covered (1)

📋 Description

A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.

🎯 Affected products5

  • pip/ansible-core:< 2.16.19rc1
  • pip/ansible-core:>= 2.17.0b1, < 2.18.18rc1
  • pip/ansible-core:>= 2.19.0b1, < 2.19.11rc1
  • pip/ansible-core:>= 2.20.0b1, < 2.20.7rc1
  • pip/ansible-core:>= 2.21.0b1, < 2.21.1rc1

🔗 References (7)