Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
The following practices would help for avoiding exposure to this flaw: 1) Prioritize the default JSON import format instead of YAML. 2) Avoid importing YAML files from untrusted sources.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 15 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Jun 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 09 Jun 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. | |
| Title | Awxkit: path traversal via yaml !include directive | |
| First Time appeared |
Redhat
Redhat ansible Automation Platform |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:/a:redhat:ansible_automation_platform:2 | |
| Vendors & Products |
Redhat
Redhat ansible Automation Platform |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-06-25T22:58:42.628Z
Reserved: 2026-06-09T07:23:36.530Z
Link: CVE-2026-52902
Updated: 2026-06-09T16:09:34.247Z
Status : Awaiting Analysis
Published: 2026-06-09T10:16:44.830
Modified: 2026-06-09T13:49:39.993
Link: CVE-2026-52902
OpenCVE Enrichment
Updated: 2026-06-09T20:15:06Z