CyberRota
← Ana sayfaya dön

CVE-2026-52902

MEDIUM · CVSS 4.7 EPSS %0.12

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-06-09T10:16:44.830 · Çekilme zamanı: 2026-06-30T18:15:28.730390+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-52902
Severity
MEDIUM
CVSS
4.7
EPSS
%0.12

Orijinal NVD Açıklaması

A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction.