Bug 2544510 (CVE-2026-103754) - CVE-2026-103754 ansible-runner: ansible-runner: path traversal and symlink escape in unstream_dir() allows file write outside the target directory
Summary: CVE-2026-103754 ansible-runner: ansible-runner: path traversal and symlink es...
Keywords:
Status: NEW
Alias: CVE-2026-103754
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-10-01 10:39 UTC by OSIDB Bzimport
Modified: 2026-10-01 11:43 UTC (History)
8 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-10-01 10:39:11 UTC
Reported via the ansible-security list by Liqiang Ji (ISCAS / SQUARE Research Group).

Module: src/ansible_runner/utils/streaming.py, function unstream_dir().

unstream_dir() performs a custom ("fancy") extraction to preserve permissions and symlinks. Two defects:
1. CWE-59 (link following): a symlink member's target is read verbatim from the archive content and re-created with os.symlink() without validation, so it can point outside target_directory (e.g. '../outside' or an absolute path). A subsequent member extracted through that symlink lands outside target_directory (arbitrary write escape).
2. CWE-22 (path traversal): out_path = os.path.join(target_directory, info.filename) is built from the unsanitized member name. ZipFile.extract() sanitizes the arcname, but os.utime()/os.chmod() operate on the raw out_path, so a member named '../victim' changes mtime/permissions on a file outside target_directory.

Exploitability: in the standard AWX/AAP topology the transmit stream is produced by the trusted controller (stream_dir only encodes pre-existing symlinks) and the controller->executor path is authenticated, so there this is defense-in-depth hardening. It is directly relevant to deployments that feed untrusted input into ansible-runner's Worker() path.

Upstream: https://github.com/ansible/ansible-runner
Fix PR: https://github.com/ansible/ansible-runner/pull/1550
Confirmed present in 2.4.3 and devel.


Note You need to log in before you can comment on or make changes to this bug.