GHSA-2qw3-2wv6-p64x
GitHub Security Advisory
Path traversal in saltstack
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
A specially crafted url can be created which leads to a directory traversal in the salt file server.
A malicious user can read an arbitrary file from a Salt master’s filesystem.
Affected Packages
PyPI
salt
Affected versions:
0
(fixed in 3005.5)
PyPI
salt
Affected versions:
3006.0
(fixed in 3006.6)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: September 18, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.