{"schema_version":"1.7.5","id":"GHSA-w8p5-mx5w-cpqj","published":"2026-06-05T09:33:46Z","modified":"2026-07-23T15:11:38.566563365Z","aliases":["CVE-2026-11332","PYSEC-2026-3458"],"summary":"ansible-core: Argument injection in ansible-galaxy role install leads to arbitrary code execution","details":"A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.","affected":[{"package":{"name":"ansible-core","ecosystem":"PyPI","purl":"pkg:pypi/ansible-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.16.19rc1"}]}],"versions":["0.0.1a1","2.11.0","2.11.0b1","2.11.0b2","2.11.0b3","2.11.0b4","2.11.0rc1","2.11.0rc2","2.11.1","2.11.10","2.11.10rc1","2.11.11","2.11.11rc1","2.11.12","2.11.12rc1","2.11.1rc1","2.11.2","2.11.2rc1","2.11.3","2.11.3rc1","2.11.4","2.11.4rc1","2.11.5","2.11.5rc1","2.11.6","2.11.6rc1","2.11.7","2.11.7rc1","2.11.8","2.11.8rc1","2.11.9","2.11.9rc1","2.12.0","2.12.0b1","2.12.0b2","2.12.0rc1","2.12.1","2.12.10","2.12.10rc1","2.12.1rc1","2.12.2","2.12.2rc1","2.12.3","2.12.3rc1","2.12.4","2.12.4rc1","2.12.5","2.12.5rc1","2.12.6","2.12.6rc1","2.12.7","2.12.7rc1","2.12.8","2.12.8rc1","2.12.9","2.12.9rc1","2.13.0","2.13.0b0","2.13.0b1","2.13.0rc1","2.13.1","2.13.10","2.13.10rc1","2.13.11","2.13.11rc1","2.13.12","2.13.12rc1","2.13.13","2.13.13rc1","2.13.1rc1","2.13.2","2.13.2rc1","2.13.3","2.13.3rc1","2.13.4","2.13.4rc1","2.13.5","2.13.5rc1","2.13.6","2.13.6rc1","2.13.7","2.13.7rc1","2.13.8","2.13.8rc1","2.13.9","2.13.9rc1","2.14.0","2.14.0b1","2.14.0b2","2.14.0b3","2.14.0rc1","2.14.0rc1.post0","2.14.0rc2","2.14.1","2.14.10","2.14.10rc1","2.14.11","2.14.11rc1","2.14.12","2.14.12rc1","2.14.13","2.14.14","2.14.14rc1","2.14.15","2.14.15rc1","2.14.16","2.14.16rc1","2.14.17","2.14.17rc1","2.14.18","2.14.18rc1","2.14.1rc1","2.14.2","2.14.2rc1","2.14.3","2.14.3rc1","2.14.4","2.14.4rc1","2.14.5","2.14.5rc1","2.14.6","2.14.6rc1","2.14.7","2.14.7rc1","2.14.8","2.14.8rc1","2.14.9","2.14.9rc1","2.15.0","2.15.0b1","2.15.0b2","2.15.0b3","2.15.0rc1","2.15.0rc2","2.15.1","2.15.10","2.15.10rc1","2.15.11","2.15.11rc1","2.15.12","2.15.12rc1","2.15.13","2.15.13rc1","2.15.1rc1","2.15.2","2.15.2rc1","2.15.3","2.15.3rc1","2.15.4","2.15.4rc1","2.15.5","2.15.5rc1","2.15.6","2.15.6rc1","2.15.7","2.15.7rc1","2.15.8","2.15.9","2.15.9rc1","2.16.0","2.16.0b1","2.16.0b2","2.16.0rc1","2.16.1","2.16.10","2.16.10rc1","2.16.11","2.16.11rc1","2.16.12","2.16.12rc1","2.16.13","2.16.13rc1","2.16.14","2.16.14rc1","2.16.15","2.16.15rc1","2.16.16","2.16.16rc1","2.16.17","2.16.17rc1","2.16.18","2.16.18rc1","2.16.1rc1","2.16.2","2.16.3","2.16.3rc1","2.16.4","2.16.4rc1","2.16.5","2.16.5rc1","2.16.6","2.16.7","2.16.7rc1","2.16.8","2.16.8rc1","2.16.9","2.16.9rc1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-w8p5-mx5w-cpqj/GHSA-w8p5-mx5w-cpqj.json"}},{"package":{"name":"ansible-core","ecosystem":"PyPI","purl":"pkg:pypi/ansible-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.17.0b1"},{"fixed":"2.18.18rc1"}]}],"versions":["2.17.0","2.17.0b1","2.17.0rc1","2.17.0rc2","2.17.1","2.17.10","2.17.10rc1","2.17.11","2.17.11rc1","2.17.12","2.17.12rc1","2.17.13","2.17.13rc1","2.17.14","2.17.14rc1","2.17.1rc1","2.17.2","2.17.2rc1","2.17.2rc2","2.17.3","2.17.3rc1","2.17.4","2.17.4rc1","2.17.5","2.17.5rc1","2.17.6","2.17.6rc1","2.17.7","2.17.7rc1","2.17.8","2.17.8rc1","2.17.9","2.17.9rc1","2.18.0","2.18.0b1","2.18.0rc1","2.18.0rc2","2.18.1","2.18.10","2.18.10rc1","2.18.11","2.18.11rc1","2.18.12","2.18.12rc1","2.18.13","2.18.13rc1","2.18.14","2.18.14rc1","2.18.15","2.18.15rc1","2.18.16","2.18.16rc1","2.18.17","2.18.17rc1","2.18.1rc1","2.18.2","2.18.2rc1","2.18.3","2.18.3rc1","2.18.4","2.18.4rc1","2.18.5","2.18.5rc1","2.18.6","2.18.6rc1","2.18.7","2.18.7rc1","2.18.8","2.18.8rc1","2.18.9","2.18.9rc1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-w8p5-mx5w-cpqj/GHSA-w8p5-mx5w-cpqj.json"}},{"package":{"name":"ansible-core","ecosystem":"PyPI","purl":"pkg:pypi/ansible-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.19.0b1"},{"fixed":"2.19.11rc1"}]}],"versions":["2.19.0","2.19.0b1","2.19.0b2","2.19.0b3","2.19.0b4","2.19.0b5","2.19.0b6","2.19.0b7","2.19.0rc1","2.19.0rc2","2.19.1","2.19.10","2.19.10rc1","2.19.1rc1","2.19.2","2.19.2rc1","2.19.3","2.19.3rc1","2.19.4","2.19.4rc1","2.19.5","2.19.5rc1","2.19.6","2.19.6rc1","2.19.7","2.19.7rc1","2.19.8","2.19.8rc1","2.19.9","2.19.9rc1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-w8p5-mx5w-cpqj/GHSA-w8p5-mx5w-cpqj.json"}},{"package":{"name":"ansible-core","ecosystem":"PyPI","purl":"pkg:pypi/ansible-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.20.0b1"},{"fixed":"2.20.7rc1"}]}],"versions":["2.20.0","2.20.0b1","2.20.0b2","2.20.0rc1","2.20.0rc2","2.20.0rc3","2.20.1","2.20.1rc1","2.20.2","2.20.2rc1","2.20.3","2.20.3rc1","2.20.4","2.20.4rc1","2.20.5","2.20.5rc1","2.20.6","2.20.6rc1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-w8p5-mx5w-cpqj/GHSA-w8p5-mx5w-cpqj.json"}},{"package":{"name":"ansible-core","ecosystem":"PyPI","purl":"pkg:pypi/ansible-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.21.0b1"},{"fixed":"2.21.1rc1"}]}],"versions":["2.21.0","2.21.0b1","2.21.0b2","2.21.0b3","2.21.0rc1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-w8p5-mx5w-cpqj/GHSA-w8p5-mx5w-cpqj.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-11332"},{"type":"WEB","url":"https://github.com/ansible/ansible/pull/87070"},{"type":"WEB","url":"https://github.com/ansible/ansible/commit/edee59aa15abcc74d920bb3e9c3835ab8db05a2f"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-11332"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2485379"},{"type":"PACKAGE","url":"https://github.com/ansible/ansible"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11332.json"}],"database_specific":{"cwe_ids":["CWE-88"],"github_reviewed":true,"github_reviewed_at":"2026-07-16T19:30:13Z","nvd_published_at":"2026-06-05T09:16:26Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}