A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.
Update ansible-core to 2.16.19rc1; ansible-core to 2.18.18rc1; ansible-core to 2.19.11rc1; ansible-core to 2.20.7rc1; ansible-core to 2.21.1rc1 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanansible-core: Argument injection in ansible-galaxy role install leads to arbitrary code execution affects ansible-core (pip), ansible-core (pip), ansible-core (pip), ansible-core (pip), ansible-core (pip). Severity is high. A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.
AI coding agents often install or upgrade packages automatically in pip. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| ansible-corepip |
A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.
Update ansible-core to 2.16.19rc1; ansible-core to 2.18.18rc1; ansible-core to 2.19.11rc1; ansible-core to 2.20.7rc1; ansible-core to 2.21.1rc1 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanansible-core: Argument injection in ansible-galaxy role install leads to arbitrary code execution affects ansible-core (pip), ansible-core (pip), ansible-core (pip), ansible-core (pip), ansible-core (pip). Severity is high. A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.
AI coding agents often install or upgrade packages automatically in pip. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| ansible-corepip |
| <2.16.19rc1 |
| 2.16.19rc1 |
| ansible-corepip | >=2.17.0b1,<2.18.18rc1 | 2.18.18rc1 |
|---|
| ansible-corepip | >=2.19.0b1,<2.19.11rc1 | 2.19.11rc1 |
|---|
| ansible-corepip | >=2.20.0b1,<2.20.7rc1 | 2.20.7rc1 |
|---|
| ansible-corepip | >=2.21.0b1,<2.21.1rc1 | 2.21.1rc1 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| <2.16.19rc1 |
| 2.16.19rc1 |
| ansible-corepip | >=2.17.0b1,<2.18.18rc1 | 2.18.18rc1 |
|---|
| ansible-corepip | >=2.19.0b1,<2.19.11rc1 | 2.19.11rc1 |
|---|
| ansible-corepip | >=2.20.0b1,<2.20.7rc1 | 2.20.7rc1 |
|---|
| ansible-corepip | >=2.21.0b1,<2.21.1rc1 | 2.21.1rc1 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard