Junglewise Threat Intelligence

CVE-2026-12398: Red Hat galaxy_ng command injection in legacy role import API

CVE-2026-12398 · Severity: high · CVSS 7.5 · Published 2026-06-16

Vendors: Ansible, PyPI, Red Hat.

Executive brief

Galaxy NG, a component of the Ansible Automation Platform used for managing automation content, contains a security flaw in its legacy role import feature. If this optional feature is enabled, an authenticated user could use a specially crafted repository name to run unauthorized commands on the underlying server. This could lead to a full system takeover, data theft, or disruption of automation services.

Technical details

A command injection vulnerability exists in the `do_git_checkout()` function within the legacy role import API (v1) of galaxy_ng. The root cause is the interpolation of unsanitized git reference names (branches or tags) into shell commands executed via `subprocess.run()` with `shell=True`. An authenticated attacker who controls a git repository can trigger this by creating a branch or tag name containing shell metacharacters (e.g., semicolons or backticks). Successful exploitation results in remote code execution (RCE) on the pulp worker process. This vulnerability is only exploitable if the non-default configuration `GALAXY_ENABLE_LEGACY_ROLES` is set to True.

Affected products

  • Ansible galaxy-ng <= 4.9.2

Timeline

  • 2026-06-16: disclosed: Initial disclosure and NVD publication
  • 2026-06-16: advisory: GitHub Advisory published

References

Related threats