PYSEC-2026-3550

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/awxkit/PYSEC-2026-3550.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2026-3550
Aliases
Published
2026-08-04T11:34:41.532108Z
Modified
2026-08-04T14:30:15.025925047Z
Severity
  • 4.7 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
awxkit has a path traversal vulnerability
Details

A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction.

References

Affected packages

PyPI / awxkit

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
24.6.1

Affected versions

13.*
13.0.0
14.*
14.0.0
14.1.0
15.*
15.0.0
15.0.1
16.*
16.0.0
17.*
17.0.0
17.0.1
17.1.0
18.*
18.0.0
19.*
19.0.0
19.1.0
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.*
20.0.1
20.1.0
21.*
21.0.0
21.1.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
22.*
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.*
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.*
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/awxkit/PYSEC-2026-3550.yaml"