THREAT OPS › Threat News › [GHSA] GHSA-cxgv-hp74-jj7r (high) — Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)
[GHSA] GHSA-cxgv-hp74-jj7r (high) — Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)
GHSA-cxgv-hp74-jj7r Severity: high CVE: CVE-2026-55074
Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)
Through version 1.3.0, the jailexec connection plugin's put_file resolved a transfer's destination to a path on the jail host (<jail filesystem root> + <destination>) and ran mkdir -p and mv there as root on the host. Those commands foll
Indicators of compromise
- CVE-2026-55074cve
Original source: https://github.com/advisories/GHSA-cxgv-hp74-jj7r