Bug 2466760 (CVE-2026-44192) - CVE-2026-44192 ansible-lightspeed: Ansible Lightspeed MCP Server: Remote Code Execution and Data Exfiltration via Path Traversal
Summary: CVE-2026-44192 ansible-lightspeed: Ansible Lightspeed MCP Server: Remote Code...
Keywords:
Status: NEW
Alias: CVE-2026-44192
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-05 15:13 UTC by OSIDB Bzimport
Modified: 2026-07-22 12:01 UTC (History)
10 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-05-05 15:13:06 UTC
A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server. This vulnerability, known as path traversal, allows an attacker to manipulate an AI agent through indirect prompt injection. By doing so, the attacker can cause the server to write files to unauthorized locations on the user's system. This can result in the exposure of sensitive host information and enable the attacker to execute malicious commands, potentially leading to a full system compromise.


Note You need to log in before you can comment on or make changes to this bug.