FlawAtlas
Search the atlas
CVE-2025-62348 High

Salt junos Module Vulnerable to Code Injection via Specially Crafted YAML Payload

Salt's junos execution module contained an unsafe YAML decode/load usage. A specially crafted YAML payload processed by the junos module could lead to unintended code execution under the context of the Salt process.

Exploit probability 0.2%
Published July 7, 2026
Required by Not available
Last source change July 7, 2026

02 / AFFECTED SOFTWARE

Affected packages

PyPI salt

235 explicit affected versions

PyPI salt

235 explicit affected versions

04 / EVIDENCE

Source records

Open Source Vulnerabilities GHSA-77w2-v593-vxvv

Salt's junos execution module contained an unsafe YAML decode/load usage. A specially crafted YAML payload processed by the junos module could lead to unintended code execution under the context of the Salt process.

View original source
Open Source Vulnerabilities PYSEC-2026-1894

Salt's junos execution module contained an unsafe YAML decode/load usage. A specially crafted YAML payload processed by the junos module could lead to unintended code execution under the context of the Salt process.

View original source

05 / REFERENCES

Further evidence