FlawAtlas
Search the atlas
CVE-2025-22238 Moderate

Salt vulnerable to directory traversal attack in minion file cache creation

Directory traversal attack in minion file cache creation. The master's default cache is vulnerable to a directory traversal attack. Which could be leveraged to write or overwrite 'cache' files outside of the cache directory.

Exploit probability 0.3%
Published July 7, 2026
Required by Not available
Last source change July 7, 2026

02 / AFFECTED SOFTWARE

Affected packages

PyPI salt

20 explicit affected versions

PyPI salt

20 explicit affected versions

04 / EVIDENCE

Source records

Open Source Vulnerabilities GHSA-r546-h3ff-q585

Directory traversal attack in minion file cache creation. The master's default cache is vulnerable to a directory traversal attack. Which could be leveraged to write or overwrite 'cache' files outside of the cache directory.

View original source
Open Source Vulnerabilities PYSEC-2026-1901

Directory traversal attack in minion file cache creation. The master's default cache is vulnerable to a directory traversal attack. Which could be leveraged to write or overwrite 'cache' files outside of the cache directory.

View original source

05 / REFERENCES

Further evidence