Back

CRITICAL

Arbitrary Remote Code Execution via Plugin Catalog Abuse

Published Aug 1, 2025

Description

A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying host if a plugin directory is set in Vault’s configuration. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.

Affected products

Remediation

Red Hat statement

The impact has been set to Important rather than Critical as this vulnerability requires a privileged user with write access to sys/audit in the root namespace. The execution also requires the SHA256 digest of the target file, which makes the attack complexity high. However, a malicious operator can possibly reproduce the file’s contents and compute its hash using the sys/audit-hash endpoint.

Red Hat mitigation

No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.

Metrics

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner HashiCorp
Published Aug 1, 2025
Updated Aug 1, 2025
Reserved Jun 11, 2025
CISA Vulnrichment
Updated Aug 1, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Aug 1, 2025
GHSA-MR4H-QF9J-F665