VDB
Sign up
CRITICAL9.6

PYSEC-2026-529

Salt vulnerable to directory traversal attack in file receiving method

Quick fix

PYSEC-2026-529 — salt: upgrade to the fixed version with the command below.

pip install --upgrade 'salt>=3006.12'

Details

Directory traversal vulnerability in recv_file method allows arbitrary files to be written to the master cache directory.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/salt
Introduced in: 3006.0rc1Fixed in: 3006.12
Fixpip install --upgrade 'salt>=3006.12'

References