CVE-2021-4041: Red Hat Ansible Runner

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the ansible_runner.interface.run_command, can lead to parameters getting executed as host's shell command. A developer could unintentionally write code that gets executed in the host rather than the virtual environment.

Affected products

  • Red Hat Ansible Runner: before 2.1.0 (fixed in 2.1.0); version 2.1.0 only

Published 2022-08-24. Last modified 2026-06-17.