VDB
Sign up
HIGH8.1

PYSEC-2026-1897

Salt vulnerable to arbitrary event injection

Quick fix

PYSEC-2026-1897 — salt: upgrade to the fixed version with the command below.

pip install --upgrade 'salt>=3006.12'

Details

Arbitrary event injection on Salt Master. The master's "_minion_event" method can be used by and authorized minion to send arbitrary events onto the master's event bus.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/salt
Introduced in: 3006.0rc1Fixed in: 3006.12
Fixpip install --upgrade 'salt>=3006.12'

References