Medium severity5.9NVD Advisory· Published Oct 1, 2026· Updated Oct 1, 2026
CVE-2026-103754
CVE-2026-103754
Description
A flaw was found in ansible-runner. The unstream_dir() function, which receives and extracts a streamed zip archive on the worker side of the ansible-runner transmit/worker protocol, re-creates symbolic links from archive content without validating the link target and applies chmod() and utime() to an unsanitized filesystem path derived from the archive member name. A crafted archive processed by a worker that consumes attacker-influenced input can create files, create symbolic links, or change permissions outside the intended target directory, which can be leveraged toward code execution.
Affected products
2Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.