CVE-2025-6000
Arbitrary Remote Code Execution via Plugin Catalog Abuse
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying host if a plugin directory is set in Vault’s configuration. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
Un operador privilegiado de Vault dentro del espacio de nombres raíz con permiso de escritura en {{sys/audit}} puede obtener la ejecución de código en el host subyacente si se establece un directorio de complementos en la configuración de Vault. Corregido en Vault Community Edition 1.20.1 y Vault Enterprise 1.20.1, 1.19.7, 1.18.12 y 1.16.23.
These are all security issues fixed in the openbao-2.3.2-1.1 package on the GA media of openSUSE Tumbleweed.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2025-06-11 CVE Reserved
- 2025-08-01 CVE Published
- 2025-08-04 CVE Updated
- 2025-08-16 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
- CAPEC-549: Local Execution of Code
References (1)
URL | Tag | Source |
---|---|---|
https://discuss.hashicorp.com/t/hcsec-2025-14-privileged-vault-operator-may-execute-code-on-the-underlying-host/76033 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
HashiCorp Search vendor "HashiCorp" | Vault Search vendor "HashiCorp" for product "Vault" | >= 0.8.0 < 1.20.1 Search vendor "HashiCorp" for product "Vault" and version " >= 0.8.0 < 1.20.1" | en |
Affected
| ||||||
HashiCorp Search vendor "HashiCorp" | Vault Enterprise Search vendor "HashiCorp" for product "Vault Enterprise" | >= 0.8.0 < 1.20.1 Search vendor "HashiCorp" for product "Vault Enterprise" and version " >= 0.8.0 < 1.20.1" | en |
Affected
|