Description
In ansible-core 2.18.0, lookup results are marked unsafe by default to prevent Jinja expressions in returned data from being evaluated later as templates. The marker means that the data is not trusted as a template; it is not an instruction to execute unsafe code. Setting allow_unsafe_lookups=True under [defaults] skips this protection, creating a risk when an untrusted result is subsequently evaluated as a template.
ansible-core 2.19.0 changed the template trust model and stopped using this option. Official documentation schedules its removal for 2.23. Follow the template trust guidance for the version you run.
Potential impact
- On an older version that uses the option, re-evaluating an untrusted external string as a template can cause unintended variable access or execution. The result's origin and subsequent use determine the impact.
- Actions performed through templating can use the privileges of the account running Ansible on the control node.
- Disabling the global option can change older playbooks that depend on further templating of returned data. Version upgrades also require review of changes to trust handling.
Remediation
- Use
ansible --versionto check the version and active configuration file, then inspect that version'sansible-configoutput and configuration precedence. - On older versions that use the option, keep
allow_unsafe_lookups=Falseor remove the option to use its default. Review individual lookup calls withallow_unsafe=Trueseparately. Do not add an exception that treats untrusted content as an executable template. - On versions where the option is unused, such as the 2.19 series, remove unnecessary legacy configuration and review plugins and playbooks against that version's template trust guidance. Changing this option alone does not strengthen the current template protections.
- Inspect the sources of lookup results, the plugin's own behavior and the templates consuming those values. Test required playbooks to confirm that data is handled as intended. The default protection is not a sandbox that blocks every action a plugin can perform.
Examples
Before
[defaults]
allow_unsafe_lookups=True
After
[defaults]
allow_unsafe_lookups=False
Explanation:
- Before: Version 2.18.0 skips the default protection for lookup results. This effect does not apply to 2.19.0, which does not use the option.
- After: Versions that use the option retain their default protection. Review per-call exceptions and plugin behavior separately. Both examples are minimal configuration fragments without lookup input or its consumers.