---
id: CVE-2023-5189
aliases:
  - GHSA-55g2-vm3q-7w52
  - PYSEC-2026-1401
title: Ansible galaxy-importer Path Traversal vulnerability
summary: Ansible galaxy-importer Path Traversal vulnerability
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N'
vendor: galaxy-importer
product: galaxy-importer
ecosystem: pip
affected:
  - galaxy-importer <= 0.4.16
published: '2023-11-15'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-55g2-vm3q-7w52'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2023-5189'
  - url: 'https://access.redhat.com/errata/RHSA-2023:7773'
  - url: 'https://access.redhat.com/errata/RHSA-2024:1536'
  - url: 'https://access.redhat.com/errata/RHSA-2024:2010'
  - url: 'https://access.redhat.com/security/cve/CVE-2023-5189'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2234387'
  - url: 'https://github.com/ansible/galaxy-importer'
  - url: >-
      https://github.com/ansible/galaxy-importer/blob/2c5c7c05fdfb0835878234b36de32902c703616d/galaxy_importer/collection.py#L160-L165
tags:
  - osv
  - pip
epss: 0.00841
epssPercentile: 0.56042
ingestedAt: '2026-07-08T18:25:45.773Z'
---

## Overview

A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball so that when using the galaxy importer of Ansible Automation Hub, a symlink could be dropped on the disk, resulting in files being overwritten.

## Affected packages

- `galaxy-importer <= 0.4.16`

## Remediation

Refer to the advisory for the patched release.
