VDB
Sign up
HIGH7.8

PYSEC-2026-1894

Salt junos Module Vulnerable to Code Injection via Specially Crafted YAML Payload

Quick fix

PYSEC-2026-1894 — salt: upgrade to the fixed version with the command below.

pip install --upgrade 'salt>=3006.17'

Details

Salt's junos execution module contained an unsafe YAML decode/load usage. A specially crafted YAML payload processed by the junos module could lead to unintended code execution under the context of the Salt process.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/salt
Introduced in: 0Fixed in: 3006.17
Fixpip install --upgrade 'salt>=3006.17'

References