Junglewise Threat Intelligence

CVE-2026-52902: Ansible awxkit path traversal in YAML !include directive

CVE-2026-52902 · Severity: medium · CVSS 4.7 · Published 2026-06-09

Vendors: Ansible, PyPI, Red Hat.

Executive brief

awxkit is a command-line tool used to interact with Ansible AWX, a platform for managing automation. A security flaw allows a malicious YAML configuration file to trick the tool into reading other sensitive files from the user's computer. If an administrator is convinced to import a specially crafted file, their private data could be uploaded to the AWX server and exposed to unauthorized parties.

Technical details

A path traversal vulnerability exists in the YAML !include directive within awxkit. The extractFile() function in 'awxkit/yaml_file.py' uses os.path.join() with unsanitized user-controlled input from !include tags without performing path containment checks. An attacker can exploit this by providing a malicious YAML file to a user who then executes 'awx --conf.format yaml import'. This allows the attacker to read arbitrary YAML-formatted files from the local filesystem, which are then populated into AWX resource fields and potentially exposed via the AWX API or UI. The attack is limited to YAML-formatted files and requires local user interaction.

Affected products

  • Ansible awxkit <= 24.6.1
  • Red Hat Red Hat Ansible Automation Platform 2

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References