Loading market data...
← Back to CVE feed

CVE-2026-71465

LOW CVSS 3.1 View on NVD ↗

Description

RunAdHocCommand.build_args() appends limit as bare positional (args.append(limit)) instead of using args.extend(['-l', limit]) like RunJob. A limit beginning with - is parsed as an ansible CLI option. Currently limited to short-circuit flags (--version, --help) since injected element displaces required pattern positional. Would escalate if ansible-core ever defaults pattern.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Published: Sep 23, 2026 19:19 UTC Modified: Sep 24, 2026 14:51 UTC