← العودة للجدول
CVE-2026-11332
CVE-2026-11332 — A flaw was found in ansible-core. The ansible-galaxy role install command proces
📅 2026-06-05
🟠 High 🔥 No NVD Exploit Supply Chain CVSS 7.8

📋 الوصف الكامل

A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-

💻 الأنظمة المتأثرة

A flaw was

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-11332

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2026-11332 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←