{"id":"PYSEC-2026-3550","summary":"awxkit has a path traversal vulnerability","details":"A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using \"awx --conf.format yaml import\". This is a client-side vulnerability requiring user interaction.","aliases":["CVE-2026-52902","GHSA-g29c-rgq6-gxgj"],"modified":"2026-08-04T14:30:15.025925047Z","published":"2026-08-04T11:34:41.532108Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-52902"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-52902"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2486729"},{"type":"PACKAGE","url":"https://github.com/ansible/awx"},{"type":"PACKAGE","url":"https://pypi.org/project/awxkit"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-g29c-rgq6-gxgj"}],"affected":[{"package":{"name":"awxkit","ecosystem":"PyPI","purl":"pkg:pypi/awxkit"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"24.6.1"}]}],"versions":["13.0.0","14.0.0","14.1.0","15.0.0","15.0.1","16.0.0","17.0.0","17.0.1","17.1.0","18.0.0","19.0.0","19.1.0","19.2.0","19.2.1","19.2.2","19.3.0","19.4.0","20.0.1","20.1.0","21.0.0","21.1.0","21.10.0","21.10.1","21.10.2","21.11.0","21.12.0","21.13.0","21.14.0","21.2.0","21.3.0","21.4.0","21.5.0","21.6.0","21.7.0","21.8.0","21.9.0","22.0.0","22.1.0","22.2.0","22.3.0","22.4.0","22.5.0","22.6.0","22.7.0","23.0.0","23.1.0","23.2.0","23.3.0","23.3.1","23.4.0","23.5.0","23.5.1","23.6.0","23.7.0","23.8.0","23.8.1","23.9.0","24.0.0","24.1.0","24.2.0","24.3.0","24.3.1","24.4.0","24.5.0","24.6.0","24.6.1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/awxkit/PYSEC-2026-3550.yaml"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"}]}