runner/connection_plugins/ssh.py in Ansible before 1.2.3, when using ControlPersist, allows local users to redirect a ssh session via a symlink attack on a socket file with a predictable name in /tmp/.
"https://github.com/pypa/advisory-database/blob/main/vulns/ansible/PYSEC-2013-1.yaml"