VDB
Sign up
MEDIUM6.6

PYSEC-2026-1122

Ansible template injection vulnerability

Quick fix

PYSEC-2026-1122 — ansible-core: upgrade to the fixed version with the command below.

pip install --upgrade 'ansible-core>=2.14.12'

Details

A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/ansible-core
Introduced in: 0Fixed in: 2.14.12
Fixpip install --upgrade 'ansible-core>=2.14.12'

References