← Back to CVE List
CVE-2025-6000NVD
Vulnerability Summary
A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying host if a plugin directory is set in Vault’s configuration. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
CVSS v3.1 Base Metrics — Score 9.1 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredHigh
User InteractionNone
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Hashicorp Vault >= 0.8.0 and < 1.16.23
- Hashicorp Vault >= 0.8.0 and < 1.20.1
- Hashicorp Vault >= 1.17.0 and < 1.18.12
- Hashicorp Vault >= 1.19.0 and < 1.19.7
- Hashicorp Vault
- Hashicorp Vault 1.16.23
- Hashicorp Vault 1.20.1
- Hashicorp Vault 1.18.12
- Hashicorp Vault 1.19.7