FlawAtlas
Search the atlas
CVE-2025-22239 High

Salt vulnerable to arbitrary event injection

Arbitrary event injection on Salt Master. The master's "_minion_event" method can be used by and authorized minion to send arbitrary events onto the master's event bus.

Exploit probability 0.2%
Published July 7, 2026
Required by Not available
Last source change July 7, 2026

02 / AFFECTED SOFTWARE

Affected packages

PyPI salt

20 explicit affected versions

PyPI salt

20 explicit affected versions

04 / EVIDENCE

Source records

Open Source Vulnerabilities GHSA-c46w-gr7f-jm2p

Arbitrary event injection on Salt Master. The master's "_minion_event" method can be used by and authorized minion to send arbitrary events onto the master's event bus.

View original source
Open Source Vulnerabilities PYSEC-2026-1897

Arbitrary event injection on Salt Master. The master's "_minion_event" method can be used by and authorized minion to send arbitrary events onto the master's event bus.

View original source

05 / REFERENCES

Further evidence