awxkit
The official command line interface for Ansible AWX
Activity
- Latest release
- 2y ago
- Total releases
- 66
- Cadence
- ~14 days
- Last 12 months
- 0
Details
- License
- Apache-2.0
- First release
- Jun 23, 2020
| Version | Released | |
|---|---|---|
24.6.1
patch
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
24.6.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
24.5.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
24.4.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
24.3.1
patch
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
24.3.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
24.2.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
24.1.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
24.0.0
major
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
23.9.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
23.8.1
patch
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
23.8.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
23.7.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
23.6.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
23.5.1
patch
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
23.5.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
23.4.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
23.3.1
patch
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
23.3.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
23.2.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
23.1.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
23.0.0
major
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
22.7.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
22.6.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
22.5.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
22.4.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
22.3.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
22.2.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
22.1.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
22.0.0
major
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
21.14.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
21.13.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
21.12.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
21.11.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
21.10.2
patch
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
21.10.1
patch
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
21.10.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
21.9.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
21.8.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
21.7.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
21.6.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
21.5.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
21.4.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
21.3.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
21.2.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
21.1.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
21.0.0
major
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
20.1.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
20.0.1
major
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev | ||
19.4.0
minor
1 CVE
CVE-2026-52902
PYSEC-2026-3550
GHSA-g29c-rgq6-gxgj
Aug 04, 2026
awxkit has a path traversal vulnerability
4.7
/ 10
Medium
Local
High
None
Required
Unchanged
High
None
None
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction. Affected versions
13.0.0
14.0.0
14.1.0
15.0.0
15.0.1
16.0.0
17.0.0
17.0.1
17.1.0
18.0.0
19.0.0
19.1.0
+ 54 more Show less
19.2.0
19.2.1
19.2.2
19.3.0
19.4.0
20.0.1
20.1.0
21.0.0
21.1.0
21.10.0
21.10.1
21.10.2
21.11.0
21.12.0
21.13.0
21.14.0
21.2.0
21.3.0
21.4.0
21.5.0
21.6.0
21.7.0
21.8.0
21.9.0
22.0.0
22.1.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
23.0.0
23.1.0
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.6.0
23.7.0
23.8.0
23.8.1
23.9.0
24.0.0
24.1.0
24.2.0
24.3.0
24.3.1
24.4.0
24.5.0
24.6.0
24.6.1
References Updated Aug 04, 2026 · Source: OSV.dev |