PYSEC-2026-793

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/cobbler/PYSEC-2026-793.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2026-793
Aliases
Published
2026-07-06T08:03:25.826275Z
Modified
2026-07-07T11:45:43.810494422Z
Summary
Cobbler vulnerable to code injection via unsafe YAML loading
Details

The set_mgmt_parameters function in item.py in cobbler before 2.2.2 allows context-dependent attackers to execute arbitrary code via vectors related to the use of the yaml.load function instead of the yaml.safe_load function, as demonstrated using Puppet.

References

Affected packages

PyPI / cobbler

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.6.0

Affected versions

0.*
0.6.3-2

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/cobbler/PYSEC-2026-793.yaml"