VDB
Sign up
—

PYSEC-2026-793

Cobbler vulnerable to code injection via unsafe YAML loading

Quick fix

PYSEC-2026-793 — cobbler: upgrade to the fixed version with the command below.

pip install --upgrade 'cobbler>=2.6.0'

Details

The `set_mgmt_parameters` function in item.py in cobbler before 2.2.2 allows context-dependent attackers to execute arbitrary code via vectors related to the use of the `yaml.load` function instead of the `yaml.safe_load function`, as demonstrated using Puppet.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/cobbler
Introduced in: 0Fixed in: 2.6.0
Fixpip install --upgrade 'cobbler>=2.6.0'

References