GHSA-g29c-rgq6-gxgj

Suggest an improvement
Source
https://github.com/advisories/GHSA-g29c-rgq6-gxgj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-g29c-rgq6-gxgj/GHSA-g29c-rgq6-gxgj.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-g29c-rgq6-gxgj
Aliases
Published
2026-06-09T12:32:04Z
Modified
2026-08-04T14:40:53Z
Severity
  • 4.7 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
awxkit has a path traversal vulnerability
Details

A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction.

Database specific
{
    "cwe_ids":  [
        "CWE-22"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-31T16:39:05Z",
    "nvd_published_at":  "2026-06-09T10:16:44Z",
    "severity":  "MODERATE"
}
References

Affected packages

PyPI / awxkit

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
24.6.1

Affected versions

13.*
13.0.0
14.*
14.0.0
14.1.0
15.*
15.0.0
15.0.1
16.*
16.0.0
17.*
17.0.0
17.0.1
17.1.0
18.*
18.0.0
19.*
19.0.0
19.1.0
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.*
20.0.1
20.1.0
21.*
21.0.0
21.1.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
22.*
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.*
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.*
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-g29c-rgq6-gxgj/GHSA-g29c-rgq6-gxgj.json"