VDB
Sign up
MEDIUM4.2

PYSEC-2026-1901

Salt vulnerable to directory traversal attack in minion file cache creation

Quick fix

PYSEC-2026-1901 — salt: upgrade to the fixed version with the command below.

pip install --upgrade 'salt>=3006.12'

Details

Directory traversal attack in minion file cache creation. The master's default cache is vulnerable to a directory traversal attack. Which could be leveraged to write or overwrite 'cache' files outside of the cache directory.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/salt
Introduced in: 3006.0rc1Fixed in: 3006.12
Fixpip install --upgrade 'salt>=3006.12'

References