PT-2025-31661 · Hashicorp+2 · Vault Community Edition+4

Yarden Porat

·

Published

2025-08-01

·

Updated

2025-10-11

·

CVE-2025-6000

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HashiCorp Vault versions prior to 1.20.1 HashiCorp Vault versions 1.19.7 and earlier HashiCorp Vault versions 1.18.12 and earlier HashiCorp Vault versions 1.16.23 and earlier HashiCorp Vault versions 0.8.0 through 1.16.22 HashiCorp Vault versions 1.17.x HashiCorp Vault versions 1.18.x HashiCorp Vault versions 1.19.x HashiCorp Vault versions 1.20.0
Description A privileged Vault operator within the root namespace, possessing write permission to the {{sys/audit}} endpoint, may achieve code execution on the underlying host if a plugin directory is configured within Vault’s configuration. The vulnerability allows for remote code execution (RCE) via misconfigured plugin directories.
Recommendations HashiCorp Vault versions prior to 1.20.1: Upgrade to version 1.20.1 or later. HashiCorp Vault versions 1.19.7 and earlier: Upgrade to version 1.19.7 or later. HashiCorp Vault versions 1.18.12 and earlier: Upgrade to version 1.18.12 or later. HashiCorp Vault versions 1.16.23 and earlier: Upgrade to version 1.16.23 or later. HashiCorp Vault versions 0.8.0 through 1.16.22: Upgrade to version 1.20.1 or later. HashiCorp Vault versions 1.17.x: Upgrade to version 1.20.1 or later. HashiCorp Vault versions 1.18.x: Upgrade to version 1.20.1 or later. HashiCorp Vault versions 1.19.x: Upgrade to version 1.20.1 or later. HashiCorp Vault versions 1.20.0: Upgrade to version 1.20.1 or later.

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

ALT-PU-2025-12480
ALT-PU-2025-12489
BDU:2025-09562
BIT-VAULT-2025-6000
CVE-2025-6000
GHSA-MR4H-QF9J-F665
GHSA-XP75-R577-CVHP
GO-2025-3838
GO-2025-3858
OPENSUSE-SU-2025:15434-1
OPENSUSE-SU-2025:15460-1
SUSE-SU-2025:02912-1

Affected Products

Alt Linux
Red Os
Vault
Vault Community Edition
Vault Enterprise