GHSA-jpvw-p8pr-9g2x
GitHub Security Advisory
Ansible symlink attack vulnerability
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.
Affected Packages
PyPI
ansible
Affected versions:
0
(fixed in 8.5.0)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: June 18, 2025 6:25 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.