High severity7.8NVD Advisory· Published Jun 5, 2026· Updated Jun 5, 2026
CVE-2026-11332
CVE-2026-11332
Description
A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8- osv-coords6 versionspkg:rpm/opensuse/ansible-core-2.18&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ansible-core-2.19&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ansible-core-2.20&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ansible-core&distro=openSUSE%20Tumbleweedpkg:rpm/suse/ansible-core&distro=SUSE%20Linux%20Enterprise%20Server%2016.0pkg:rpm/suse/ansible-core&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0
< 2.18.18-1.1+ 5 more
- (no CPE)range: < 2.18.18-1.1
- (no CPE)range: < 2.19.11-1.1
- (no CPE)range: < 2.20.7-1.1
- (no CPE)range: < 2.21.0-3.1
- (no CPE)range: < 2.18.3-160000.3.1
- (no CPE)range: < 2.18.3-160000.3.1
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.