VDB
Sign up
MEDIUM5.0

PYSEC-2026-1900

Directory creation by malicious user in saltstack

Quick fix

PYSEC-2026-1900 — salt: upgrade to the fixed version with the command below.

pip install --upgrade 'salt>=3005.5'

Details

Syndic cache directory creation is vulnerable to a directory traversal attack in salt project which can lead a malicious attacker to create an arbitrary directory on a Salt master.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/salt
Introduced in: 0Fixed in: 3005.5
Fixpip install --upgrade 'salt>=3005.5'

References