CVE-2026-89091 - Ansible-core: ansible-core: ansible-galaxy collection install symlink path escape allows arbitrary file write / code execution
CVE ID :CVE-2026-89091 Published : Oct. 8, 2026, 10:17 p.m. | 1 hour, 12 minutes ago Description :A flaw was found in ansible-core. When installing a collection with `ansible-galaxy collection install`, the archive extractor validates member paths using lexical path normalisation...