GHSA-7j69-qfc3-2fq9
GitHub Security Advisory
Ansible template injection vulnerability
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.
Affected Packages
PyPI
ansible-core
Affected versions:
2.16.0
(fixed in 2.16.1)
PyPI
ansible-core
Affected versions:
2.15.0
(fixed in 2.15.8)
PyPI
ansible-core
Affected versions:
0
(fixed in 2.14.12)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: June 18, 2025 6:25 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.