VYPR
High severity7.8NVD Advisory· Published Jun 5, 2026· Updated Aug 20, 2026

CVE-2026-11332

CVE-2026-11332

Description

A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
ansible-corePyPI
< 2.16.19rc12.16.19rc1
ansible-corePyPI
>= 2.17.0b1, < 2.18.18rc12.18.18rc1
ansible-corePyPI
>= 2.19.0b1, < 2.19.11rc12.19.11rc1
ansible-corePyPI
>= 2.20.0b1, < 2.20.7rc12.20.7rc1
ansible-corePyPI
>= 2.21.0b1, < 2.21.1rc12.21.1rc1

Affected products

14

Patches

Vulnerability mechanics

References

17

News mentions

0

No linked articles in our index yet.