MEDIUM 6.7 PyPI

Salt's on demand pillar functionality vulnerable to arbitrary command injections

GHSA-fcr4-h6c4-rvvp · CVE-2025-22237 · PYSEC-2026-1898

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

An attacker with access to a minion key can exploit the 'on demand' pillar functionality with a specially crafted git url which could cause and arbitrary command to be run on the master with the same privileges as the master process.

Ready to move

Start Securing

Free, no credit card | First findings in minutes