Salt junos Module Vulnerable to Code Injection via Specially Crafted YAML Payload
Salt's junos execution module contained an unsafe YAML decode/load usage. A specially crafted YAML payload processed by the junos module could lead to unintended code execution under the context of the Salt process.
02 / AFFECTED SOFTWARE
Affected packages
235 explicit affected versions
235 explicit affected versions
04 / EVIDENCE
Source records
Salt's junos execution module contained an unsafe YAML decode/load usage. A specially crafted YAML payload processed by the junos module could lead to unintended code execution under the context of the Salt process.
Salt's junos execution module contained an unsafe YAML decode/load usage. A specially crafted YAML payload processed by the junos module could lead to unintended code execution under the context of the Salt process.
05 / REFERENCES
Further evidence
- https://docs.saltproject.io/en/latest/topics/releases/3006.17.html
- https://github.com/saltstack/salt
- https://github.com/saltstack/salt/issues/68469
- https://github.com/saltstack/salt/pull/68472/commits/c17fd645edef208233dcac855615fced69409a00
- https://nvd.nist.gov/vuln/detail/CVE-2025-62348
- https://github.com/advisories/GHSA-77w2-v593-vxvv
- https://pypi.org/project/salt