Executive brief
awxkit is a command-line tool used to interact with Ansible AWX, a platform for managing automation. A security flaw allows a malicious YAML configuration file to trick the tool into reading other sensitive files from the user's computer. If an administrator is convinced to import a specially crafted file, their private data could be uploaded to the AWX server and exposed to unauthorized parties.
Technical details
A path traversal vulnerability exists in the YAML !include directive within awxkit. The extractFile() function in 'awxkit/yaml_file.py' uses os.path.join() with unsanitized user-controlled input from !include tags without performing path containment checks. An attacker can exploit this by providing a malicious YAML file to a user who then executes 'awx --conf.format yaml import'. This allows the attacker to read arbitrary YAML-formatted files from the local filesystem, which are then populated into AWX resource fields and potentially exposed via the AWX API or UI. The attack is limited to YAML-formatted files and requires local user interaction.
Affected products
- Ansible awxkit <= 24.6.1
- Red Hat Red Hat Ansible Automation Platform 2
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory