Executive brief
A security flaw exists in the Ansible Lightspeed Model Context Protocol (MCP) server, a component used to integrate AI-driven automation into development workflows. An attacker can trick the AI agent into writing files to restricted areas of a user's computer. This could allow an attacker to steal sensitive information or take complete control of the affected system.
Technical details
A path traversal vulnerability (CWE-22) exists in the Ansible Lightspeed Model Context Protocol (MCP) server. The flaw is triggered via indirect prompt injection, where an attacker provides malicious input that manipulates the AI agent's behavior. This manipulation allows the server to write files to unauthorized locations on the host system. An attacker can exploit this to exfiltrate sensitive host information or achieve remote code execution by overwriting critical system files. The attack requires user interaction (UI:R) and is executed with local-level privileges (AV:L).
Affected products
- Red Hat Ansible Automation Platform 2 2.5, 2.6
- Red Hat Ansible Lightspeed Model Context Protocol (MCP) server
Timeline
- 2026-05-05: other: Vulnerability reported to Red Hat Bugzilla
- 2026-07-22: disclosed: CVE published to NVD