CVE-2025-22240

CWE-22Path Traversal5 documents4 sources
Severity
6.3MEDIUM
EPSS
0.1%
top 73.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 13

Description

Arbitrary directory creation or file deletion. In the find_file method of the GitFS class, a path is created using os.path.join using unvalidated input from the “tgt_env” variable. This can be exploited by an attacker to delete any file on the Master's process has permissions to.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:HExploitability: 0.3 | Impact: 5.9

Affected Packages2 packages

PyPIsalt3007.0rc13007.4+1
CVEListV5vmware/salt3006.x3006.12+1

🔴Vulnerability Details

4
GHSA
Salt allows arbitrary directory creation or file deletion2025-06-13
OSV
Salt allows arbitrary directory creation or file deletion2025-06-13
CVEList
CVE-2025-22240 salt advisory2025-06-13
OSV
CVE-2025-22240: Arbitrary directory creation or file deletion2025-06-13
CVE-2025-22240 (MEDIUM CVSS 6.3) | Arbitrary directory creation or fil | cvebase.io