A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying host if a plugin directory is set in Vault’s configuration. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
{
"versions": [
{
"introduced": "0.8.0"
},
{
"fixed": "1.20.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.20.0"
}
]
}[
{
"events": [
{
"introduced": "0.8.0"
},
{
"fixed": "1.16.23"
}
]
},
{
"events": [
{
"introduced": "1.17.0"
},
{
"fixed": "1.18.12"
}
]
},
{
"events": [
{
"introduced": "1.19.0"
},
{
"fixed": "1.19.7"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-6000.json"