PT-2025-47922 · Unknown+2 · Fluent-Bit+2

Published

2025-11-23

·

Updated

2026-03-19

·

CVE-2025-12972

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Fluent Bit versions prior to 4.1.1
Description The out file plugin in Fluent Bit does not properly sanitize tag values when creating output file names. If the File option is not specified, the plugin utilizes tag input, which is considered untrusted, to construct file paths. This allows attackers with network access to manipulate tags with path traversal sequences, potentially causing Fluent Bit to write files to locations outside the designated output directory. The issue enables unauthorized file writing.
Recommendations Upgrade to Fluent Bit version 4.1.1 or later.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2025-15408
BIT-FLUENT-BIT-2025-12972
CVE-2025-12972

Affected Products

Fluent-Bit
Red Os
Out File Plugin