PYSEC-2026-1903

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/salt/PYSEC-2026-1903.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2026-1903
Aliases
Published
2026-07-07T16:02:54.851955Z
Modified
2026-07-07T17:48:09.555128040Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Salt allows arbitrary directory creation or file deletion
Details

Arbitrary directory creation or file deletion. In the findfile method of the GitFS class, a path is created using os.path.join using unvalidated input from the “tgtenv” variable. This can be exploited by an attacker to delete any file on the Master's process has permissions to.

References

Affected packages

PyPI / salt

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3006.0rc1
Fixed
3006.12
Introduced
3007.0rc1
Fixed
3007.4

Affected versions

3006.*
3006.0rc1
3006.0rc2
3006.0rc3
3006.0
3006.1
3006.2
3006.3
3006.4
3006.5
3006.6
3006.7
3006.8
3006.9
3006.10
3006.11
3007.*
3007.0rc1
3007.0
3007.1
3007.2
3007.3

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/salt/PYSEC-2026-1903.yaml"