CVE-2026-103754 UNKNOWN

CVE-2026-103754

Published: 2026-10-01

Description

A flaw was found in ansible-runner. The unstream_dir() function, which receives and extracts a streamed zip archive on the worker side of the ansible-runner transmit/worker protocol, re-creates symbolic links from archive content without validating the link target and applies chmod() and utime() to an unsanitized filesystem path derived from the archive member name. A crafted archive processed by a worker that consumes attacker-influenced input can create files, create symbolic links, or change permissions outside the intended target directory, which can be leveraged toward code execution.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…