CVE-2025-6000: Hashicorp Vault
Critical severity, CVSS 9.1. EPSS: 0.9% chance of exploitation in the next 30 days.
A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying host if a plugin directory is set in Vault’s configuration. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
Affected products
- Hashicorp Vault: from 0.8.0, before 1.16.23 (fixed in 1.16.23); from 0.8.0, before 1.20.1 (fixed in 1.20.1); from 1.17.0, before 1.18.12 (fixed in 1.18.12); from 1.19.0, before 1.19.7 (fixed in 1.19.7); version 1.20.0 only
Published 2025-08-01. Last modified 2026-06-17.